CVE-2026-86763
Undergoing Analysis Undergoing Analysis - In Progress

Authorization Bypass in Snipe-IT via Livewire Importer

Vulnerability report for CVE-2026-86763, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time, while its files() and activeFile() computed properties queried the imports table with no owner or company scope. As a result, any authenticated non-superuser holding the import permission could view every Import record on the instance (original filename, file_path, filesize, import_type and creation timestamp) and could invoke the selectFile($id) Livewire action with any auto-incrementing Import ID to load another user's record, exposing its stored preview data (header_row column headers and first_row, the first data row of the CSV). Because import CSVs commonly contain personal data, asset serial numbers and license keys, this discloses sensitive information; in Full Multiple Companies Support (FMCS) deployments the disclosure also crosses company/tenant boundaries. Impact is limited to preview data rather than the full CSV file, and superusers were unaffected. Fixed in version 8.7.0, which scopes non-superuser reads to imports owned by the caller.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it From 7.0.12 (inc) to 8.6.3 (inc)
snipe-it snipe-it 8.7.0
grokability snipe-it From 7.0.12 (inc) to 8.6.3 (inc)
grokability snipe-it 8.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86763 is an authorization bypass vulnerability in Snipe-IT versions 7.0.12 through 8.6.3. It affects the Livewire importer component where authenticated non-superusers with import permission can access sensitive preview data of other users' import records. The component fails to enforce ownership or company scope when querying import records, allowing unauthorized access to metadata and partial CSV content.

Detection Guidance

To detect this vulnerability, check if your Snipe-IT instance is running a vulnerable version (7.0.12 to 8.6.3). Verify if non-superusers with import permissions can access other users' import previews. Inspect the Livewire importer component for improper authorization checks.

Impact Analysis

This vulnerability allows attackers to view sensitive data such as personal information, asset serial numbers, and license keys from other users' CSV files. The impact is limited to preview data (header rows and first data row) and does not grant full file access. In deployments with Full Multiple Companies Support, the breach can cross company boundaries.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized disclosure of personal data and sensitive information. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. The exposure of such data through this vulnerability may result in regulatory penalties and legal consequences.

Mitigation Strategies

Immediately update Snipe-IT to version 8.7.0 or later to patch the vulnerability. As a temporary measure, revoke the import permission from non-superuser roles until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86763. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart