ZeroHour

CVE-2026-86743

PoC moderate

Cross-Company Asset Acceptance Data Exposure in Snipe-IT Reports

CVSS 4.0
5.3 medium
EPSS
<1%p17
Published
()
Modified
AI analysis

Snipe-IT versions before 8.7.0 fail to scope asset acceptance report queries by company, so any authenticated user with the reports.view permission can read pending asset acceptances belonging to all companies on the instance, not just their own. The flaw is triggered by visiting the unaccepted_assets report page or downloading its CSV export, which return cross-company rows — including inventory details and assignee names — without per-row access validation. This is an authorization bypass (CWE-639, user-controlled key) that leaks confidential asset inventory and personnel data in multi-company deployments, rated medium severity (CVSS 4.0: 5.3). Only self-hosted Snipe-IT instances running versions prior to 8.7.0 with multiple companies configured are materially affected. Exploitation likelihood appears low (EPSS 0.3%, 17th percentile), and while a vendor advisory is public, no in-the-wild exploitation is known.

What to do: Upgrade Snipe-IT to version 8.7.0 or later, which scopes asset acceptance report queries per company. Review audit and access logs for unexpected access to the unaccepted_assets report page or CSV exports by users who should not see cross-company data. As a mitigation, restrict the reports.view permission to trusted staff until the upgrade is complete.

Affected
snipeitapp snipe-itbefore 8.7.0
Estimated exposure
moderate≈ thousands to low tens of thousands of self-hosted Snipe-IT instances, with only the multi-company subset actually vulnerable — Snipe-IT is a popular self-hosted open-source asset management platform where public internet scans typically reveal a few thousand exposed instances, and the cross-company leak only matters for the fraction running multi-company…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose cross-company inventory details and assignee names without per-row access validation.

Vendors
snipeitapp
Products
snipe-it
Weakness
CWE-639
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.