Description
Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and saved before the requested company_id / company_ids[] values are filtered against the actor's permitted companies (Company::getIdsForCurrentUser()). On installs using Full Multiple Companies Support (FMCS), a non-superuser holding users.create (or users.edit on a target user) can submit company identifiers for companies outside their scope — including a mix of permitted and foreign ids — causing the account row to be committed to the database before authorization is checked. Where null_company_is_floater=1 is set, the post-hoc filter leaves an empty company pivot and the account is persisted as a "floater" with cross-company visibility, allowing creation or relocation of user accounts across tenant boundaries.
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass across company boundaries
Action: Patch
AI Analysis

Impact

The vulnerability arises because API user create and update endpoints do not verify that the company identifiers supplied by the actor belong to the actor's authorized set before persisting the user record. This allows a user with the users.create or users.edit permission to assign a new or existing user to companies outside their control. When the configuration null_company_is_floater is set to 1, the pivot is cleared after authorization filtering, causing the user to be stored as a "floater" with visibility to all tenant companies. This results in unauthorized access to sensitive information and a cross‑tenant privilege escalation.

Affected Systems

The issue affects Snipe‑IT deployments from Grokability, versions 8.6.3 and earlier, when Full Multiple Companies Support is enabled. The fix is available in version 8.7.0.

Risk and Exploitability

The CVSS score of 8.3 reflects a high severity Remote API exploitation under the Normal User attack vector, with a reach that spans the entire database. Exploitation requires network access to the REST API, an account that holds users.create or users.edit, and an environment where FMCS is active and null_company_is_floater is enabled. The vulnerability is not listed in the CISA KEV catalog and its EPSS score is not available, but the high CVSS indicates a significant risk. An attacker can invoke the API, provide a mix of valid and foreign company identifiers, and create or move user accounts onto unauthorized company memberships, thereby gaining cross‑tenant access to assets.

Generated by OpenCVE AI on September 9, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Snipe‑IT to version 8.7.0 or later to apply the vendor’s patch that enforces company assignment validation before saving user records.
  • If upgrading is not yet possible, limit the privileges that non‑superusers have by revoking users.create and users.edit rights, or disable Full Multiple Companies Support so that user‑company associations cannot be modified through the API.
  • In deployments where null_company_is_floater must remain enabled, manually patch the Api\UsersController to perform a pre‑save authorization check against Company::getIdsForCurrentUser() before persisting, or set null_company_is_floater to 0 to prevent the post‑process pivot clearing that creates free‑floating users.

Generated by OpenCVE AI on September 9, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and saved before the requested company_id / company_ids[] values are filtered against the actor's permitted companies (Company::getIdsForCurrentUser()). On installs using Full Multiple Companies Support (FMCS), a non-superuser holding users.create (or users.edit on a target user) can submit company identifiers for companies outside their scope — including a mix of permitted and foreign ids — causing the account row to be committed to the database before authorization is checked. Where null_company_is_floater=1 is set, the post-hoc filter leaves an empty company pivot and the account is persisted as a "floater" with cross-company visibility, allowing creation or relocation of user accounts across tenant boundaries.
Title snipe-it before 8.7.0 Authorization Bypass via API User Create/Update
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:22:35.512Z

Reserved: 2026-09-08T11:32:11.095Z

Link: CVE-2026-86750

cve-icon Vulnrichment

Updated: 2026-09-14T13:22:31.108Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:24.030

Modified: 2026-09-14T20:30:57.460

Link: CVE-2026-86750

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:45:05Z

Weaknesses