Incorrect authorization in snipe-it - #VU145086

 

Incorrect authorization in snipe-it - #VU145086

Published: August 25, 2026


Vulnerability identifier: #VU145086
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access acceptance reminder and delete functions across company boundaries, disclose limited acceptance context, and delete pending acceptance records.

The vulnerability exists due to incorrect authorization in ReportsController::currentUserCanAccessAcceptance() when handling requests to the acceptance reminder and delete endpoints. A remote user can send a crafted request for a pending acceptance ID to access acceptance reminder and delete functions across company boundaries, disclose limited acceptance context, and delete pending acceptance records.

Exploitation requires FMCS to be enabled and the vulnerable user account to be a pivot-only user with the reports.view permission. Acceptance IDs are sequential integers, and no direct cross-company report listing access is provided by this issue.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins