Authorization Bypass in Snipe-IT Affecting User Management
CVE-2026-86750
8.3HIGH
What is CVE-2026-86750?
In Snipe-IT versions up to 8.6.3, an authorization bypass vulnerability allows non-superuser roles to manipulate user records via the REST API without proper validation. Specifically, the application fails to verify permissions against the requested company when creating or updating user records. As a result, unauthorized users can submit company identifiers that fall outside their access permissions, leading to potential data exposure and user account manipulation across different companies. This vulnerability risks the integrity and security of user data and should be promptly addressed by upgrading to version 8.7.0 or later.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
