Description
Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete (ReportsController::deleteAssetAcceptance) are not correctly scoped when Full Multiple Company Support (FMCS) is enabled. In 8.6.3 the guard ReportsController::currentUserCanAccessAcceptance() early-exits with 'return true' when '! $user->company_id' is truthy, which is the case for every pivot-only user (a user associated with companies through the company_user pivot table whose scalar users.company_id column is NULL); versions prior to 8.6.3 lacked the guard altogether. As a result, an authenticated user holding the reports.view permission can send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutable. Deletion is destructive and forfeits the acceptance audit trail for the affected item, and the reminder email exposes limited cross-company acceptance context (item name and assignment metadata) to the recipient. Acceptance IDs are sequential integers and can be enumerated. This issue is fixed in version 8.7.0.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass / Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

In Snipe‑IT versions 8.6.3 and earlier, endpoints that send acceptance‑reminder emails and delete acceptance records do not enforce proper scoping when Full Multiple Company Support (FMCS) is enabled. The access guard returns true for users whose company_id is NULL, a condition true for pivot‑only users. Consequently, any authenticated user with the reports.view permission can send reminder emails for, or permanently delete, any pending acceptance record across all companies in the installation. This action removes the acceptance audit trail and can expose limited cross‑company information through the reminder email. Acceptance IDs are sequential integers and can be enumerated, potentially enabling further information disclosure. The vulnerability is a classic instance of CWE‑863: Authorization Bypass through Role or Permission Deletion. It permits a user with a narrow permission (reports.view) to perform operations normally restricted to a specific company context, effectively elevating their privileges. The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Overall, the risk hinges on the presence of any authenticated user with reports.view permission and the ability to enable FMCS. The flaw is not a remote code execution or denial‑of‑service flaw, but it corrupts data integrity and may leak sensitive cross‑company context. The likely attack vector is a legitimate user acting within the application. An attacker would need to have an account with reports.view permission; pivot‑only users are a common scenario. The vulnerability is exploitable by simply calling the documented REST endpoints.

Affected Systems

Snipe‑IT, an open source IT asset management system published by grokability, suffers from this defect in all releases up to and including version 8.6.3. Earlier releases prior to 8.6.3 are also affected because they lack the access guard entirely. Users deploying Snipe‑IT with Full Multiple Company Support enabled may experience this problem if they have pivot‑only users.

Risk and Exploitability

The CVSS metric of 5.3 denotes medium risk; the EPSS score is not provided, so the current exploitation probability is uncertain but not zero. The vulnerability is not catalogued in CISA KEV, yet its presence in older installations combined with the existence of privileged pivot‑only users makes successful exploitation plausible. An attacker with reports.view can simply issue the POST or DELETE requests to the specified endpoints to send reminder emails or delete any acceptance record. Because acceptance IDs are sequential, enumeration can facilitate further data discovery. Once the fix is applied or mitigation steps enforced, the flaw is closed. However, until an upgrade is possible or workarounds are implemented, the system remains vulnerable to privilege escalation and data tampering.

Generated by OpenCVE AI on September 9, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Snipe‑IT 8.7.0 or later to apply the vendor patch.
  • If an immediate upgrade is not feasible, restrict the reports.view permission for all users whose company_id is NULL, preventing pivot‑only users from abusing the endpoints.
  • Alternatively, disable Full Multiple Company Support or enforce correct company scoping until the update can be applied.

Generated by OpenCVE AI on September 9, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete (ReportsController::deleteAssetAcceptance) are not correctly scoped when Full Multiple Company Support (FMCS) is enabled. In 8.6.3 the guard ReportsController::currentUserCanAccessAcceptance() early-exits with 'return true' when '! $user->company_id' is truthy, which is the case for every pivot-only user (a user associated with companies through the company_user pivot table whose scalar users.company_id column is NULL); versions prior to 8.6.3 lacked the guard altogether. As a result, an authenticated user holding the reports.view permission can send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutable. Deletion is destructive and forfeits the acceptance audit trail for the affected item, and the reminder email exposes limited cross-company acceptance context (item name and assignment metadata) to the recipient. Acceptance IDs are sequential integers and can be enumerated. This issue is fixed in version 8.7.0.
Title snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:46.692Z

Reserved: 2026-09-08T11:31:38.679Z

Link: CVE-2026-86747

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:43.363Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:23.553

Modified: 2026-09-14T20:33:55.553

Link: CVE-2026-86747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:45:16Z

Weaknesses