CVE-2026-86750
Analyzed Analyzed - Analysis Complete

Snipe-IT Authorization Bypass via Company Assignment in REST API

Vulnerability report for CVE-2026-86750, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and saved before the requested company_id / company_ids[] values are filtered against the actor's permitted companies (Company::getIdsForCurrentUser()). On installs using Full Multiple Companies Support (FMCS), a non-superuser holding users.create (or users.edit on a target user) can submit company identifiers for companies outside their scope β€” including a mix of permitted and foreign ids β€” causing the account row to be committed to the database before authorization is checked. Where null_company_is_floater=1 is set, the post-hoc filter leaves an empty company pivot and the account is persisted as a "floater" with cross-company visibility, allowing creation or relocation of user accounts across tenant boundaries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Snipe-IT versions 8.6.3 and earlier. It allows a non-superuser with users.create or users.edit permissions to assign users to companies outside their permitted scope via the REST API. The issue occurs because user records are saved to the database before verifying if the company assignment is authorized. This can lead to unauthorized user persistence with cross-company visibility, especially when the null_company_is_floater setting is enabled.

Detection Guidance

Check Snipe-IT version with: grep -r "version" /path/to/snipe-it/config/app.php. If version is <= 8.6.3, the system is vulnerable. Review API logs for unauthorized user creation or company assignment attempts, particularly for users with users.create or users.edit permissions.

Impact Analysis

An attacker could create or modify user accounts and assign them to unauthorized companies, potentially gaining access to sensitive data across tenant boundaries. This could lead to data breaches, unauthorized access, or privilege escalation within the Snipe-IT system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection and access control. It may result in non-compliance with GDPR (data protection), HIPAA (healthcare data), or other regulations mandating strict access controls and audit trails.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. Review and restrict users.create and users.edit permissions to only necessary personnel. Disable null_company_is_floater=1 if not required. Audit recent user creations and company assignments for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86750. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart