CVE-2026-86747
Analyzed Analyzed - Analysis Complete

Unauthorized Asset Acceptance Deletion in Snipe-IT

Vulnerability report for CVE-2026-86747, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete (ReportsController::deleteAssetAcceptance) are not correctly scoped when Full Multiple Company Support (FMCS) is enabled. In 8.6.3 the guard ReportsController::currentUserCanAccessAcceptance() early-exits with 'return true' when '! $user->company_id' is truthy, which is the case for every pivot-only user (a user associated with companies through the company_user pivot table whose scalar users.company_id column is NULL); versions prior to 8.6.3 lacked the guard altogether. As a result, an authenticated user holding the reports.view permission can send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutable. Deletion is destructive and forfeits the acceptance audit trail for the affected item, and the reminder email exposes limited cross-company acceptance context (item name and assignment metadata) to the recipient. Acceptance IDs are sequential integers and can be enumerated. This issue is fixed in version 8.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86747 is an authorization bypass vulnerability in Snipe-IT, an IT asset management system. It affects versions up to 8.6.3 when Full Multiple Company Support (FMCS) is enabled. The issue occurs because the ReportsController::currentUserCanAccessAcceptance() function incorrectly grants access to pivot-only users (users with NULL company_id) by early-exiting with 'return true'. This allows authenticated users with reports.view permission to send acceptance-reminder emails or delete pending acceptance records for items owned by other companies, bypassing proper company scoping.

Detection Guidance

To detect this vulnerability, check if your Snipe-IT instance is running version 8.6.3 or earlier. Verify if Full Multiple Company Support (FMCS) is enabled and if pivot-only users exist. Look for unauthorized access attempts to the endpoints POST /reports/unaccepted_assets/sent_reminder and DELETE /reports/unaccepted_assets/{acceptanceId}/delete.

  • Check Snipe-IT version: grep -r "version" /path/to/snipe-it/config/app.php or check the web interface footer.
  • Review user roles: Identify users with reports.view permission and pivot-only users (users.company_id is NULL).
  • Inspect logs for suspicious activity on the affected endpoints, especially from pivot-only users.
Impact Analysis

An attacker with reports.view permission could exploit this to delete pending acceptance records, destroying audit trails for asset acceptance. They could also send reminder emails containing limited cross-company acceptance context (item name and assignment metadata) to recipients. Since acceptance IDs are sequential, they can be enumerated, making exploitation easier. The impact includes data loss, compromised audit integrity, and potential unauthorized information exposure.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized deletion of acceptance records, which may violate data retention and audit trail requirements in GDPR and HIPAA. GDPR requires proper data handling and audit trails, while HIPAA mandates secure and traceable records. The loss of audit trails due to unauthorized deletions could result in non-compliance with these regulations.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later to patch the vulnerability. If upgrading is not immediately possible, disable Full Multiple Company Support (FMCS) temporarily until the upgrade is completed.

  • Upgrade Snipe-IT: Follow the official upgrade guide to version 8.7.0 or higher.
  • Disable FMCS: Temporarily disable FMCS in the Snipe-IT configuration if an upgrade cannot be performed immediately.
  • Audit user permissions: Review and restrict reports.view permissions to only necessary users.
  • Monitor for exploitation: Check logs for unauthorized access attempts to the affected endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86747. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart