CVE-2026-86752: snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries against cross-company assets if the query-layer scope were bypassed or refactored.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
snipe-itto a version that resolves this vulnerability.Fixed in 8.7.0
Event History
Frequently Asked Questions
Which users could exploit this issue?
An attacker needs a valid snipe-it session and the assets.audit permission. The issue concerns attempts to create audit log entries for assets belonging to a different company or instance scope.
Are default deployments known to be directly exploitable?
The described exposure depends on the query-layer FMCS scope being bypassed or altered through refactoring. The available information does not establish that the normal default query-layer behavior alone permits cross-company audit writes.
What is the recommended remediation?
Upgrade snipe-it to version 8.7.0 or later. Until upgrading, restrict assets.audit permission to trusted users and avoid changes that weaken or bypass query-layer company scoping.