CVE-2026-86774: Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only assets.files permission can mutate shared model file attachments across company boundaries and bypass the dedicated models.files permission intended to restrict file management on the shared Asset Model catalog.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.7.0 - Compensating control
Until upgraded, restrict users’ ability to upload/delete file attachments on Asset Model records so that only users granted the intended models.files permission can manage attachments (because AssetModelPolicy files() cascades from assets.files in versions before 8.7.0).
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who has the assets.files permission but does not have the dedicated models.files permission can exploit it. The issue affects file attachment management on shared Asset Model records, including records across company boundaries.
What access does an attacker need?
The attacker needs a valid authenticated account and the assets.files permission. No user interaction is required, and exploitation can be performed over the network.
What can an attacker do with successful exploitation?
They can upload and delete file attachments on Asset Model records despite lacking models.files permission. This allows them to alter attachments in the shared Asset Model catalog across company boundaries.
Which versions are affected and what is the remediation?
Snipe-IT versions before 8.7.0 are affected. Upgrade to version 8.7.0 or later.