Authorization bypass through user-controlled key in snipe-it - #VU142575

 

Authorization bypass through user-controlled key in snipe-it - #VU142575

Published: August 14, 2026


Vulnerability identifier: #VU142575
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify records across company boundaries and send reminder emails to users in other companies.

The vulnerability exists due to authorization bypass through user-controlled key in checkout-acceptance report actions when handling crafted requests referencing sequential acceptance IDs under full multiple company support. A remote user can send a specially crafted request to modify records across company boundaries and send reminder emails to users in other companies.

Exploitation requires the reports.view permission and full multiple company support to be enabled.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.6.2

External References

Related Security Bulletins