Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.
Published: 2026-07-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Snipe‑IT is an IT asset and license management system. In versions earlier than 8.6.2, the Accessories API create endpoint mass‑assigns all request parameters—including the company_id—directly onto the Accessory model. Because company_id is mass‑assignable and Full Multiple Companies Support is enabled, a user with low‑privileged API access in one company can forge a request that creates accessory records under another company. This missing authorization check (CWE‑862) lets the attacker add or modify asset data outside their tenant, violating data integrity and potentially confidentiality. The flaw was addressed in release v8.6.2.

Affected Systems

All Snipe‑IT installations built by grokability that are running any version earlier than 8.6.2, provided that the Full Multiple Companies Support feature is active. Users with API access in a tenant can exploit the flaw against any other tenant on the same instance.

Risk and Exploitability

The CVSS score of 8.5 categorises the issue as high severity. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated API request and knowledge of a target company’s identifier, making it a privilege‑escalation scenario. The potential impact for multi‑tenant operations remains significant.

Generated by OpenCVE AI on July 28, 2026 at 08:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Snipe‑IT installation to version 8.6.2 or a later release.
  • If an immediate upgrade is not possible, disable Full Multiple Companies Support or exclude the company_id field from the mass‑assignable attributes until the patch is applied.
  • Limit privileges of users so that they cannot set or modify the company_id on accessory creation requests.

Generated by OpenCVE AI on July 28, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pwpj-p52h-q484 Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
History

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.
Title Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-10T20:58:22.265Z

Reserved: 2026-06-12T18:42:02.224Z

Link: CVE-2026-54329

cve-icon Vulnrichment

Updated: 2026-07-10T20:46:22.001Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:15:06Z

Weaknesses