CVE-2026-86743
PoC moderateCross-Company Asset Acceptance Data Exposure in Snipe-IT Reports
Snipe-IT versions before 8.7.0 fail to scope asset acceptance report queries by company, so any authenticated user with the reports.view permission can read pending asset acceptances belonging to all companies on the instance, not just their own. The flaw is triggered by visiting the unaccepted_assets report page or downloading its CSV export, which return cross-company rows — including inventory details and assignee names — without per-row access validation. This is an authorization bypass (CWE-639, user-controlled key) that leaks confidential asset inventory and personnel data in multi-company deployments, rated medium severity (CVSS 4.0: 5.3). Only self-hosted Snipe-IT instances running versions prior to 8.7.0 with multiple companies configured are materially affected. Exploitation likelihood appears low (EPSS 0.3%, 17th percentile), and while a vendor advisory is public, no in-the-wild exploitation is known.
What to do: Upgrade Snipe-IT to version 8.7.0 or later, which scopes asset acceptance report queries per company. Review audit and access logs for unexpected access to the unaccepted_assets report page or CSV exports by users who should not see cross-company data. As a mitigation, restrict the reports.view permission to trusted staff until the upgrade is complete.
| snipeitapp snipe-it | before 8.7.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose cross-company inventory details and assignee names without per-row access validation.
- Vendors
- snipeitapp
- Products
- snipe-it
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.