Junglewise Threat Intelligence

CVE-2026-86752: snipe-it asset audit endpoints authorization bypass

CVE-2026-86752 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Grokability Snipe-It. Vendors: Snipeitapp.

Executive brief

snipe-it is an open-source asset management system used to track inventory and IT equipment across organizations. Versions before 8.7.0 contain a flaw in asset audit endpoints that fails to properly validate user permissions at the policy level, instead relying solely on database-layer filtering. An authenticated attacker with audit permissions could potentially write audit log entries against assets they should not have access to if the database filter were bypassed or refactored.

Technical details

The vulnerability is a class of incorrect authorization (CWE-863) in snipe-it's asset audit endpoints. Three shipped audit endpoints in AssetsController (web GET/POST and API POST) invoke authorize('audit', Asset::class) with the class rather than the specific asset instance, bypassing per-instance FMCS (Fixed Multi-Company Scoping) checks that the AssetPolicy::audit method would enforce. Per-asset authorization is currently enforced entirely at the query layer via the CompanyableScope global scope, which filters Asset lookups. An attacker with a valid session, assets.audit role permission, and knowledge of a cross-company asset ID could write audit entries across company boundaries if the query-layer scope were removed or bypassed. The fix adds explicit per-instance authorize('audit', $asset) calls after route model binding, enforcing FMCS at the policy layer independently. Patch available in version 8.7.0.

Affected products

  • grokability snipe-it before 8.7.0

Timeline

  • 2026-08-24: disclosed
  • 2026-09-09: advisory
  • 2026-09-09: patched: Fix available in version 8.7.0

References

Related threats