Executive brief
Snipe-IT is an open-source asset and inventory management system. A flaw in its predefined kit checkout feature allows a non-superuser with permission to checkout assets—if that user belongs to multiple companies—to assign assets from one company to users in a different company, bypassing the multi-tenant isolation controls that are enforced on all other checkout methods. This could allow unauthorized asset transfers and data exposure across company boundaries in multi-tenant deployments.
Technical details
The vulnerability is an authorization bypass (CWE-863) in the PredefinedKitCheckoutService component. The service processes kit checkouts but fails to call the canCheckoutTo() method on items before persisting them to the database, unlike all other checkout paths (single, bulk, API, accessory, license, consumable). With Full Multiple Company Support (FMCS) enabled, an authenticated non-superuser with assets.checkout permission who belongs to at least two companies can POST to /kits/{kit}/checkout with a target user belonging only to company B, and have a company-A asset assigned to that user, violating tenant isolation. The vulnerability requires FMCS to be enabled, the actor to be a multi-company member, and an available asset model in the kit. The issue was introduced when the service was created in 2019 and was fixed in version 8.7.2 by adding company isolation checks before checkout.
Affected products
- Snipe-IT Snipe-IT before 8.7.2
Timeline
- 2026-09-10: disclosed: CVE-2026-88894 published
- 2026: patched: Fixed in version 8.7.2