GHSA-8w8c-8mx9-52cw: Medium severity composer/snipe/snipe-it vulnerability

Published Aug 28, 2026
·
Updated

Impact When Full Multiple Companies Support and scopelocationsfmcs are both enabled, the API endpoint for creating locations can still create a child location under a parent location from a different company. The code detects the invalid parent/child company mismatch, but it appears not to return immediately, so the request continues and the record is still saved. The equivalent Web flow correctly rejects the same relationship.

This breaks the expected company-boundary enforcement for location hierarchies under FMCS. It allows cross-company parent/child relationships to be inserted into the location tree, which can affect hierarchy integrity, downstream business logic, and the consistency of company isolation between the Web and API interfaces.

Patches Patched in https://github.com/grokability/snipe-it/commit/9a8cbd6e00613a726b639a97a1da71b3c54f9489

Affected Software

1 affected componentFixes available
composer/snipe/snipe-it<=8.6.1
8.6.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/snipe/snipe-it to a version that resolves this vulnerability.

    Fixed in 8.6.2
  2. Upgrade

    Upgrade grokability/snipe-it to a version that resolves this vulnerability.

    Patch 9a8cbd6e00613a726b639a97a1da71b3c54f9489

Event History

Aug 28, 2026
Advisory Published
via GitHub·06:01 PM
Data Sourced
via GitHub·06:01 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

The issue affects deployments where both Full Multiple Companies Support and scope_locations_fmcs are enabled. It applies to location creation through the API; the equivalent Web flow rejects the invalid cross-company relationship.

2

What access does an attacker need?

An attacker needs low-privilege access and network access to the API. They can create a child location whose parent belongs to a different company, despite the expected company-boundary validation.

3

What should be done to remediate this issue?

Apply the patch containing commit 9a8cbd6e00613a726b639a97a1da71b3c54f9489. Until patched, restrict access to the API location-creation endpoint for users who do not need it, particularly in deployments with both affected company-scoping options enabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203