PT-2026-89012 · Git+1 · Snipe-It

·

CVE-2026-86743

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted assets report page or CSV export to disclose cross-company inventory details and assignee names without per-row access validation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86743
GHSA-7XRR-XM47-RC6W

Affected Products

Snipe-It