CVE-2026-85616

    Dashboard / Vulnerabilities / CVE-2026-85616

    CVE-2026-85616

    Published: 4 Sept 2026Last Modified: 18 Sept 2026

    Summary: Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance

    Details: Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 4d06e8176883e2d8f1c91afe77ec0511959ceb91

    Affected versions

    v8.6.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-85616 | CVE-DB