CVE-2026-86747: Incorrect Authorization in grokability snipe-it
Snipe-IT versions up to and including 8.6.3 have an incorrect authorization vulnerability in report acceptance endpoints when Full Multiple Company Support (FMCS) is enabled. Authenticated users with reports.view permission can send acceptance reminder emails and delete pending acceptance records across companies. Deletion removes audit trails, and reminder emails leak limited cross-company acceptance context. The issue is fixed in version 8.7.0.
AI Analysis
Technical Summary
Snipe-IT, an open source IT asset management system, has an authorization flaw in versions up to 8.6.3 affecting the POST /reports/unaccepted_assets/sent_reminder and DELETE /reports/unaccepted_assets/{acceptanceId}/delete endpoints. When FMCS is enabled, the authorization guard either is missing (pre-8.6.3) or incorrectly implemented (8.6.3), allowing users with reports.view permission to act on acceptance records belonging to any company. This leads to unauthorized sending of reminder emails and destructive deletion of acceptance records, compromising audit trails and exposing limited acceptance context. Acceptance IDs are sequential and enumerable. The vulnerability is resolved in version 8.7.0.
Potential Impact
An authenticated user with reports.view permission can send acceptance reminder emails and delete acceptance records for any company in the installation, bypassing intended company scoping. Deletion is destructive, removing audit trails for the acceptance records. Reminder emails leak limited information about acceptance items and assignments across companies. This could lead to unauthorized data exposure and loss of audit integrity.
Mitigation Recommendations
Upgrade to Snipe-IT version 8.7.0 or later, where this authorization issue is fixed. Until then, restrict reports.view permission to trusted users only. Patch status is not yet confirmed by vendor advisory; check the vendor's official resources for current remediation guidance.
CVE-2026-86747: Incorrect Authorization in grokability snipe-it
Description
Snipe-IT versions up to and including 8.6.3 have an incorrect authorization vulnerability in report acceptance endpoints when Full Multiple Company Support (FMCS) is enabled. Authenticated users with reports.view permission can send acceptance reminder emails and delete pending acceptance records across companies. Deletion removes audit trails, and reminder emails leak limited cross-company acceptance context. The issue is fixed in version 8.7.0.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/grokability/snipe-itRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Snipe-IT, an open source IT asset management system, has an authorization flaw in versions up to 8.6.3 affecting the POST /reports/unaccepted_assets/sent_reminder and DELETE /reports/unaccepted_assets/{acceptanceId}/delete endpoints. When FMCS is enabled, the authorization guard either is missing (pre-8.6.3) or incorrectly implemented (8.6.3), allowing users with reports.view permission to act on acceptance records belonging to any company. This leads to unauthorized sending of reminder emails and destructive deletion of acceptance records, compromising audit trails and exposing limited acceptance context. Acceptance IDs are sequential and enumerable. The vulnerability is resolved in version 8.7.0.
Potential Impact
An authenticated user with reports.view permission can send acceptance reminder emails and delete acceptance records for any company in the installation, bypassing intended company scoping. Deletion is destructive, removing audit trails for the acceptance records. Reminder emails leak limited information about acceptance items and assignments across companies. This could lead to unauthorized data exposure and loss of audit integrity.
Mitigation Recommendations
Upgrade to Snipe-IT version 8.7.0 or later, where this authorization issue is fixed. Until then, restrict reports.view permission to trusted users only. Patch status is not yet confirmed by vendor advisory; check the vendor's official resources for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-08T11:31:38.679Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa164b5acd9273b49685941
Added to database: 09/09/2026, 13:52:53 UTC
Last enriched: 09/09/2026, 14:23:18 UTC
Last updated: 09/10/2026, 00:24:39 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.