Junglewise Threat Intelligence

CVE-2026-86747: Snipe-IT authorization bypass in asset acceptance reports

CVE-2026-86747 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an open-source IT asset management system used to track corporate hardware and licenses. A flaw in the report acceptance endpoints allows authenticated users with basic report-viewing permissions to delete acceptance records and send reminder emails across company boundaries, destroying audit trails and exposing cross-company asset information when multiple company support is enabled.

Technical details

The vulnerability is an authorization bypass (CWE-863) in ReportsController::currentUserCanAccessAcceptance(), which fails to properly validate company scope for pivot-only users under Full Multiple Company Support (FMCS). The guard function early-exits with 'return true' when the user's scalar company_id column is null—a condition true for all users assigned to companies via the company_user pivot table. This affects POST /reports/unaccepted_assets/sent_reminder and DELETE /reports/unaccepted_assets/{acceptanceId}/delete endpoints. An authenticated attacker with reports.view permission can enumerate sequential acceptance IDs and delete any pending acceptance record or trigger reminder emails exposing cross-company item metadata, regardless of company ownership. The fix, shipped in version 8.7.0, rewrites the guard to delegate to Company::isCurrentUserHasAccess() and properly consult pivot membership.

Affected products

  • Snipe IT Snipe-IT up to and including 8.6.3

Timeline

  • 2026-08-24: disclosed: GitHub security advisory GHSA-p5wx-p3vv-g6p2 published
  • 2026-09-09: advisory: CVE-2026-86747 published on NVD
  • 2026: patched: Fixed in version 8.7.0

References

Related threats