Authorization Bypass in Snipe-IT IT Asset Management System
CVE-2026-86747
5.3MEDIUM
What is CVE-2026-86747?
The Snipe-IT IT asset management system has a vulnerability affecting versions up to and including 8.6.3, where report acceptance endpoints lack proper authorization controls when Full Multiple Company Support (FMCS) is enabled. This flaw allows authenticated users with the 'reports.view' permission to send acceptance reminder emails and permanently delete any pending acceptance record across different companies. The affected functionality exposes sensitive acceptance context and compromises auditability due to the destructive nature of deletions. This critical issue has been addressed in version 8.7.0.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
