Authorization Bypass in Snipe-IT Affecting User Management
CVE-2026-86750

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86750?

In Snipe-IT versions up to 8.6.3, an authorization bypass vulnerability allows non-superuser roles to manipulate user records via the REST API without proper validation. Specifically, the application fails to verify permissions against the requested company when creating or updating user records. As a result, unauthorized users can submit company identifiers that fall outside their access permissions, leading to potential data exposure and user account manipulation across different companies. This vulnerability risks the integrity and security of user data and should be promptly addressed by upgrading to version 8.7.0 or later.

Affected Version(s)

snipe-it 0 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

christopherfi-dev
snipe
.