PatchSiren cyber security CVE debrief
CVE-2026-86747 grokability CVE debrief
CVE-2026-86747 is a vulnerability in Snipe-IT, an open-source IT asset management system. In versions up to and including 8.6.3, certain report acceptance endpoints are not correctly scoped when Full Multiple Company Support (FMCS) is enabled, allowing an authenticated user with the reports.view permission to send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutable.
- Vendor
- grokability
- Product
- snipe-it
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for Snipe-IT installations, particularly those with FMCS enabled and users with the reports.view permission, should assess exposure and apply the fix in version 8.7.0.
Why it matters
CVE-2026-86747 is a vulnerability in Snipe-IT that allows an authenticated user with the reports.view permission to access report acceptance endpoints without proper scoping when FMCS is enabled. Defenders should prioritize verifying exposure and applying the fix in version 8.7.0.
- Potential unauthorized access to report acceptance endpoints
- Possible exposure of limited cross-company acceptance context
- Permanent deletion of acceptance records, forfeiting audit trails
Technical summary
The vulnerability exists in the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder and DELETE /reports/unaccepted_assets/{acceptanceId}/delete in Snipe-IT versions up to and including 8.6.3. An authenticated user with the reports.view permission can exploit this vulnerability to send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutable.
Defensive priority
Defenders should prioritize verifying exposure and applying the fix in version 8.7.0, focusing on systems with FMCS enabled and users with the reports.view permission.
Recommended defensive actions
- Verify if the system has FMCS enabled and users with the reports.view permission
- Apply the fix in version 8.7.0
- Monitor for potential abuse of report acceptance endpoints
- Review and update user permissions and access controls
- Perform a thorough review of system configurations and user roles
- Implement additional logging and monitoring for report acceptance endpoints
- Review and update incident response plans to address potential exploitation
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. Vendor advisory and third-party advisory references are also available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86747 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86747
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86747 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86747
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-p5wx-p3vv-g6p2
[email protected] - Exploit, Vendor Advisory, Mitigation
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-authorization-bypass-via-pivot-only-user
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.