Description
Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can retrieve cross-tenant data including requested asset names, requester display names and profile links, locations, and expected check-in dates without parameter manipulation.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update Software
AI Analysis

Impact

Snipe-IT versions prior to 8.7.0 lack proper company‑scope filtering on the GET /hardware/requested endpoint when Full Multiple Company Support is enabled. The flaw allows users with the assets.view permission in an authenticated session to view pending asset requests from all companies, exposing the names of requested items, requester display names, profile links, locations, and expected check‑in dates. The vulnerability results in the disclosure of sensitive cross‑tenant data to any authenticated user possessing the view permission, representing an unauthorized information leakage.

Affected Systems

The affected product is Snipe‑IT, provided by grokability. Versions released before 8.7.0 are impacted, especially when the Full Multiple Company Support feature is active. Users running those versions should review their installation date and consult the vendor for a fix.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity; the EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated access, as the flaw requires an authenticated user with assets.view permissions and does not involve parameter manipulation. If an attacker possesses legitimate credentials, they can retrieve cross‑tenant data via standard API calls, making remediation a priority for organizations with multi‑company deployments.

Generated by OpenCVE AI on September 9, 2026 at 15:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later to restore proper company‑scoping in the requested‑assets endpoint
  • If upgrading is not immediately feasible, disable Full Multiple Company Support or restrict it to trusted users only
  • Restrict or remove the assets.view permission from users who do not require view access to asset requests or cross‑company data

Generated by OpenCVE AI on September 9, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can retrieve cross-tenant data including requested asset names, requester display names and profile links, locations, and expected check-in dates without parameter manipulation.
Title Snipe-IT before 8.7.0 Cross-Company Read via requested-assets
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-200
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:14.732Z

Reserved: 2026-09-08T11:33:02.642Z

Link: CVE-2026-86767

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:34.219Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:27.133

Modified: 2026-09-16T20:28:24.340

Link: CVE-2026-86767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:30:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor