Impact
In Snipe‑IT versions 8.6.3 and earlier, endpoints that send acceptance‑reminder emails and delete acceptance records do not enforce proper scoping when Full Multiple Company Support (FMCS) is enabled. The access guard returns true for users whose company_id is NULL, a condition true for pivot‑only users. Consequently, any authenticated user with the reports.view permission can send reminder emails for, or permanently delete, any pending acceptance record across all companies in the installation. This action removes the acceptance audit trail and can expose limited cross‑company information through the reminder email. Acceptance IDs are sequential integers and can be enumerated, potentially enabling further information disclosure. The vulnerability is a classic instance of CWE‑863: Authorization Bypass through Role or Permission Deletion. It permits a user with a narrow permission (reports.view) to perform operations normally restricted to a specific company context, effectively elevating their privileges. The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Overall, the risk hinges on the presence of any authenticated user with reports.view permission and the ability to enable FMCS. The flaw is not a remote code execution or denial‑of‑service flaw, but it corrupts data integrity and may leak sensitive cross‑company context. The likely attack vector is a legitimate user acting within the application. An attacker would need to have an account with reports.view permission; pivot‑only users are a common scenario. The vulnerability is exploitable by simply calling the documented REST endpoints.
Affected Systems
Snipe‑IT, an open source IT asset management system published by grokability, suffers from this defect in all releases up to and including version 8.6.3. Earlier releases prior to 8.6.3 are also affected because they lack the access guard entirely. Users deploying Snipe‑IT with Full Multiple Company Support enabled may experience this problem if they have pivot‑only users.
Risk and Exploitability
The CVSS metric of 5.3 denotes medium risk; the EPSS score is not provided, so the current exploitation probability is uncertain but not zero. The vulnerability is not catalogued in CISA KEV, yet its presence in older installations combined with the existence of privileged pivot‑only users makes successful exploitation plausible. An attacker with reports.view can simply issue the POST or DELETE requests to the specified endpoints to send reminder emails or delete any acceptance record. Because acceptance IDs are sequential, enumeration can facilitate further data discovery. Once the fix is applied or mitigation steps enforced, the flaw is closed. However, until an upgrade is possible or workarounds are implemented, the system remains vulnerable to privilege escalation and data tampering.
OpenCVE Enrichment