Cross-Tenant Data Exposure in Snipe-IT by Vendor Grokability
CVE-2026-86767
5.3MEDIUM
What is CVE-2026-86767?
Snipe-IT versions preceding 8.7.0 exhibit a serious flaw where the GET /hardware/requested endpoint fails to enforce company scope filtering when Full Multiple Company Support is activated. This oversight permits authenticated users possessing the assets.view permission to access and read pending asset requests across all companies. An attacker can exploit this vulnerability to retrieve sensitive cross-tenant information, including requested asset names, requester display names, profile links, locations, and expected check-in dates without needing to manipulate parameters. As a result, this vulnerability poses a significant risk to data privacy and confidentiality within multi-tenant environments.
Affected Version(s)
snipe-it 8.6.3 < 8.7.0
snipe-it 8.7.0
