Impact
Snipe‑IT prior to version 8.6.2 contains a vulnerability that enables an authenticated user possessing only the reports.view permission to bypass authorization for checkout‑acceptance report actions. The flaw arises from a null check on a legacy company identifier column, allowing the attacker to enumerate sequential acceptance IDs, soft‑delete records, or trigger reminder emails that belong to other companies. This weakness can lead to unauthorized data modification and privacy violations across company boundaries.
Affected Systems
The affected product is Snipe‑IT, specifically all releases before 8.6.2. The vulnerability is only present when Full Multiple Company Support is enabled, which means that organizations using earlier versions with this feature are at risk. Users must verify if they are running any Snipe‑IT version older than 8.6.2 and if the multi‑company mode is active.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity flaw; however, the EPSS score is not available, so the real‑world exploitation likelihood is uncertain. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be authenticated with a valid user account that has the reports.view permission, suggesting that insider or compromised accounts pose an immediate threat. Once access is gained, enumeration of acceptance IDs can be performed without additional reconnaissance, making the attack vector straightforward for someone with the necessary permissions.
OpenCVE Enrichment