CVE-2026-86743
Analyzed Analyzed - Analysis Complete

Snipe-IT Information Disclosure via Unscoped Asset Reports

Vulnerability report for CVE-2026-86743, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose cross-company inventory details and assignee names without per-row access validation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86743 is an authorization bypass in Snipe-IT versions before 8.7.0. It allows authenticated users with the reports.view permission to access pending asset acceptance reports across all companies in a multi-company environment. The vulnerability occurs because report endpoints do not enforce company-level scoping, enabling users to view sensitive cross-company data such as inventory details and assignee names.

Detection Guidance

Check Snipe-IT logs for unauthorized access to /reports/unaccepted_assets or POST /reports/unaccepted_assets endpoints. Monitor for CSV exports of pending asset acceptances by users without company-scoped permissions.

Impact Analysis

If you use Snipe-IT with multiple companies, an attacker with reports.view access could steal sensitive inventory and assignee data from other companies. This could lead to unauthorized disclosure of proprietary asset information or personal data, depending on what is stored in the system.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by enabling unauthorized access to personal or sensitive data across companies. Unauthorized disclosure of such data may result in legal penalties, regulatory fines, or reputational damage due to non-compliance with data protection standards.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later to apply the company scoping fix. Temporarily restrict reports.view permissions to trusted users until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86743. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart