Junglewise Threat Intelligence

CVE-2026-86763: Snipe-IT Livewire importer authorization bypass

CVE-2026-86763 · Severity: low · CVSS 3.5 · Published 2026-09-09

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an open-source IT asset management system used to track and manage hardware, software licenses, and inventory. An authentication flaw in the CSV import feature allows authenticated users with import permissions to view other users' uploaded CSV files and preview their contents—including employee names, asset serial numbers, and license keys—even if those files belong to different users or company divisions. This could expose sensitive corporate data stored in upload files.

Technical details

The Livewire importer component (App\Livewire\Importer) failed to scope database queries to the authenticated user's own imports. The files() and activeFile() computed properties queried the imports table without owner or company filtering, allowing any authenticated non-superuser with the import permission to enumerate all Import records by ID (auto-incrementing integers) and invoke selectFile($id) with arbitrary IDs. This exposed the stored preview data: CSV header_row and first_row (first data row), along with metadata like original filename, file path, filesize, import type, and creation timestamp. In multi-tenant deployments with Full Multiple Companies Support (FMCS), the disclosure crossed tenant boundaries. The vulnerability was introduced in v7.0.12 and fixed in v8.7.0 by adding owner-scope filtering to computed properties and returning null for cross-user records.

Affected products

  • Snipe Snipe-IT >= 7.0.12, <= 8.6.3

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in version 8.7.0

References

Related threats