Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2.
Published: 2026-07-10
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to create a child location under a parent location belonging to a different company when Full Multiple Companies Support and the scope_locations_fmcs feature are enabled in Snipe-IT. The API location creation endpoint detects the mismatch but does not abort the request, resulting in a location being created with a parent from an unrelated company. This bypasses the intended company boundary checks and can lead to unauthorized placement of assets or misleading inventory data. The weakness is classified as CWE-863.

Affected Systems

Vulnerable versions are Snipe-IT releases prior to 8.6.2 when Full Multiple Companies Support affected product is the Snipe-IT asset management system developed by Grokability, with the specific issue fixed in release v8.6.2.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate. EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data. The attack appears to occur via the authenticated location-creation API endpoint; therefore, the attacker must possess sufficient permissions to create locations. Based on the description, it is inferred that the attack vector is via authorized API usage, and the vulnerability essentially allows circumventing company boundary validation, potentially leading to data integrity violations across company partitions.

Generated by OpenCVE AI on July 29, 2026 at 10:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Snipe-IT to version 8.6.2 or later to apply the vendor patch that enforces company boundary checks during location creation.
  • If an immediate upgrade is not possible_fmcs setting so that child locations cannot be created across company boundaries until the patch is applied.
  • Conduct an audit of existing locations to ensure that no child locations currently reference a parent from a different company, and correct any violations.

Generated by OpenCVE AI on July 29, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2.
Title Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-13T18:22:44.183Z

Reserved: 2026-06-16T22:10:37.609Z

Link: CVE-2026-55472

cve-icon Vulnrichment

Updated: 2026-07-13T18:22:39.517Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:30:05Z

Weaknesses