Junglewise Threat Intelligence

CVE-2026-85616: Snipe-IT authorization bypass in checkout-acceptance report

CVE-2026-85616 · Severity: high · CVSS 8.5 · Published 2026-09-04

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an open-source asset tracking and management system used by organizations to track inventory, equipment, and hardware across multiple business units. When the Full Multiple Company Support feature is enabled, authenticated users with report-viewing permissions can bypass tenant isolation controls to soft-delete pending checkout records or send reminder emails for other companies' assets. This breaks the cross-company access restrictions the multi-tenant feature is designed to enforce.

Technical details

The vulnerability is an authorization bypass (CWE-639) caused by an incorrect check on a legacy database column. When Full Multiple Company Support is enabled, normal users have users.company_id set to NULL and store their company membership in a pivot table instead. The vulnerable endpoints DELETE /reports/unaccepted_assets/{id}/delete and POST /reports/unaccepted_assets/sent_reminder fail to check this pivot table; instead, they check the NULL scalar column and treat it as "no scoping required," granting cross-company access. Any authenticated user with the reports.view permission can enumerate sequential acceptance IDs and exploit this to soft-delete acceptances or trigger reminder emails for other companies. The vulnerability was fixed in commit 802067f on 2026-06-12 and shipped in version 8.6.2.

Affected products

  • Snipe Snipe-IT before 8.6.2

Timeline

  • 2026-09-04: disclosed
  • 2026-06-12: patched: Fix committed; shipped in v8.6.2

References

Related threats