CVE-2026-85616: Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance
Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.companyid column.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.6.2 - Compensating control
If you cannot upgrade immediately, restrict access so that only authorized users for a given company can use the checkout-acceptance report actions when Full Multiple Company Support is enabled.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments running a Snipe-IT version before 8.6.2 with Full Multiple Company Support enabled are affected. The vulnerable actions are checkout-acceptance report actions.
What access does an attacker need?
An attacker must be authenticated and have the reports.view permission. No user interaction is required, and the attacker can enumerate sequential acceptance IDs.
What can an attacker do across company boundaries?
The attacker can soft-delete checkout acceptances belonging to other companies or trigger reminder emails for them. The issue affects authorization boundaries between companies.
How can I determine whether exploitation may have occurred?
Review checkout-acceptance activity for soft deletions or reminder emails affecting acceptances owned by a different company than the user performing the action. Sequential acceptance-ID access by accounts with reports.view permission is also relevant to investigate.