Authorization Bypass in Snipe-IT IT Asset Management System
CVE-2026-86747

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86747?

The Snipe-IT IT asset management system has a vulnerability affecting versions up to and including 8.6.3, where report acceptance endpoints lack proper authorization controls when Full Multiple Company Support (FMCS) is enabled. This flaw allows authenticated users with the 'reports.view' permission to send acceptance reminder emails and permanently delete any pending acceptance record across different companies. The affected functionality exposes sensitive acceptance context and compromises auditability due to the destructive nature of deletions. This critical issue has been addressed in version 8.7.0.

Affected Version(s)

snipe-it 0 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

christopherfi-dev
snipe
.