← Terug naar overzicht

Snipe-IT versions prior to 8.6.2 contain an authorization bypass vulnerability affecting the checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users holding only the reports.view permission can exploit sequential acceptance ID enumeration to access records belonging to other companies. The flaw stems from a null check on the legacy users.company_id column, which fails to enforce proper company-level isolation. Exploitation allows unauthorized users to soft-delete acceptances or trigger reminder emails for acceptances outside their own company scope. The vulnerability requires authentication but no elevated privileges beyond reports.view. It is an insecure direct object reference (IDOR) style flaw compounded by missing authorization checks. A fix has been released in Snipe-IT version 8.6.2. Organizations using multi-company configurations are particularly at risk and should upgrade immediately.

Affected products

  • Snipe-IT

Related CVE's

  • CVE-2026-85616

Categories

  • Enterprise Applications
  • Identity & Access