Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose personal data and assigned licenses, /users/bulkeditsave can modify out-of-scope profiles, and /users/merge can soft-delete users and transfer assigned assets. This issue is fixed in version 8.6.3.
Published: 2026-08-19
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Prior to version 8.6.3, Snipe‑IT allows a company‑scoped user operating in FMCS floater mode to bypass tenant isolation and access or modify the data of users whose company_id is null. Broad API queries and bulk web actions do not consistently apply the isCurrentUserHasAccess check, so an attacker can retrieve personal details and assigned licenses via the /api/v1/users and /api/v1/users/{id}/licenses endpoints, alter out‑of‑scope profiles with /users/bulkeditsave, and soft‑delete users while transferring assigned assets using /users/merge. This flaw enables the disclosure of sensitive information and the unauthorized manipulation of user accounts and asset ownership.

Affected Systems

Snipe‑IT (grokability:snipe‑it) versions prior to 8.6.3 are affected. The vulnerability specifically impacts the FMCS floater mode configuration and is mitigated by upgrading to any release numbered 8.6.3 or later.

Risk and Exploitability

The CVSS score of 7.6 indicates a high‑severity issue, and EPSS data is not available, but the problem remains publicly known and unpatched in affected installations. The likely attack vector is through authenticated API calls or web interfaces that a company‑scoped user can perform, which suggests remote exploitation without privileged credentials beyond legitimate account access. The vulnerability is not listed in the CISA KEV catalog, but its capacity to expose personal data and alter licenses makes it a critical risk for organizations relying on strict tenant isolation.

Generated by OpenCVE AI on August 20, 2026 at 12:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Snipe‑IT to version 8.6.3 or newer, which includes the fix for the tenant isolation bypass.
  • Reconfigure the system to disable or restrict FMCS floater mode for users that should not have cross‑company access, ensuring that isCurrentUserHasAccess is enforced on all API endpoints.
  • Audit the configuration of user roles and API usage for endpoints /api/v1/users, /api/v1/users/{id}/licenses, /users/bulkeditsave and /users/merge to confirm that access control policies are correctly applied.

Generated by OpenCVE AI on August 20, 2026 at 12:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c6w2-j4wq-mvwg Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode
History

Wed, 19 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose personal data and assigned licenses, /users/bulkeditsave can modify out-of-scope profiles, and /users/merge can soft-delete users and transfer assigned assets. This issue is fixed in version 8.6.3.
Title Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-19T18:42:40.792Z

Reserved: 2026-06-16T23:52:12.057Z

Link: CVE-2026-55643

cve-icon Vulnrichment

Updated: 2026-08-19T18:42:37.551Z

cve-icon NVD

Status : Received

Published: 2026-08-19T19:17:20.533

Modified: 2026-08-19T19:17:20.533

Link: CVE-2026-55643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T13:00:13Z

Weaknesses