CVE-2026-86743
Dashboard / Vulnerabilities / CVE-2026-86743
Summary: Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report
Details: Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose cross-company inventory details and assignee names without per-row access validation.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86743.json, https://github.com/grokability/snipe-it/security/advisories/GHSA-7xrr-xm47-rc6w, https://nvd.nist.gov/vuln/detail/CVE-2026-86743, https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-authorization-bypass-via-asset-acceptance-report
Affected packages
Package
Name:
Purl:
