Cross-Tenant Data Exposure in Snipe-IT by Vendor Grokability
CVE-2026-86767

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86767?

Snipe-IT versions preceding 8.7.0 exhibit a serious flaw where the GET /hardware/requested endpoint fails to enforce company scope filtering when Full Multiple Company Support is activated. This oversight permits authenticated users possessing the assets.view permission to access and read pending asset requests across all companies. An attacker can exploit this vulnerability to retrieve sensitive cross-tenant information, including requested asset names, requester display names, profile links, locations, and expected check-in dates without needing to manipulate parameters. As a result, this vulnerability poses a significant risk to data privacy and confidentiality within multi-tenant environments.

Affected Version(s)

snipe-it 8.6.3 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

khoadb175
.