MEDIUM 5.3 NVD
CVE-2026-86743
Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acce
Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose cross-company inventory details and assignee names without per-row access validation.
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-7xrr-xm47-rc6w
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-authorization-bypass-via-asset-
- https://github.com/grokability/snipe-it/security/advisories/GHSA-7xrr-xm47-rc6w
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-09 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.