CVE-2026-85616
Received Received - Intake

Authorization Bypass in Snipe-IT via Report Actions

Vulnerability report for CVE-2026-85616, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
grokability snipe-it to 8.6.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-85616 is an authorization bypass vulnerability in Snipe-IT versions before 8.6.2. It affects the Full Multiple Company Support feature, which is meant to isolate data between different companies. The flaw allows authenticated users with reports.view permission to bypass company boundaries by exploiting a null check on a legacy column. This enables them to enumerate acceptance IDs and perform actions like soft-deleting records or sending reminder emails for other companies.

Detection Guidance

To detect this vulnerability, check Snipe-IT versions prior to 8.6.2. Verify if Full Multiple Company Support is enabled and if users with reports.view permission can access or modify records outside their company scope. Review audit logs for soft-deleted acceptance records or unexpected reminder emails across companies.

Impact Analysis

This vulnerability allows unauthorized users to delete or modify checkout-acceptance records belonging to other companies. Attackers could disrupt workflows by soft-deleting pending acceptances or sending unwanted reminder emails. It does not directly expose confidential data but can lead to data integrity issues and operational disruptions.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to records, potentially violating data integrity requirements in GDPR and HIPAA. It undermines tenant isolation, which may conflict with regulatory expectations for access controls and audit trails. Organizations using Snipe-IT with FMCS should patch immediately to maintain compliance.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.6.2 or later. If upgrading is not possible, revoke reports.view permissions from non-cross-company users and audit soft-deleted acceptance records for unauthorized deletions. Monitor for suspicious activity in the checkout-acceptance report actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85616. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart