Impact
The vulnerability arises because API user create and update endpoints do not verify that the company identifiers supplied by the actor belong to the actor's authorized set before persisting the user record. This allows a user with the users.create or users.edit permission to assign a new or existing user to companies outside their control. When the configuration null_company_is_floater is set to 1, the pivot is cleared after authorization filtering, causing the user to be stored as a "floater" with visibility to all tenant companies. This results in unauthorized access to sensitive information and a cross‑tenant privilege escalation.
Affected Systems
The issue affects Snipe‑IT deployments from Grokability, versions 8.6.3 and earlier, when Full Multiple Companies Support is enabled. The fix is available in version 8.7.0.
Risk and Exploitability
The CVSS score of 8.3 reflects a high severity Remote API exploitation under the Normal User attack vector, with a reach that spans the entire database. Exploitation requires network access to the REST API, an account that holds users.create or users.edit, and an environment where FMCS is active and null_company_is_floater is enabled. The vulnerability is not listed in the CISA KEV catalog and its EPSS score is not available, but the high CVSS indicates a significant risk. An attacker can invoke the API, provide a mix of valid and foreign company identifiers, and create or move user accounts onto unauthorized company memberships, thereby gaining cross‑tenant access to assets.
OpenCVE Enrichment