PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86767 grokability CVE debrief

CVE-2026-86767 is a vulnerability in Snipe-IT versions before 8.7.0 that allows authenticated users with assets.view permission to read pending asset requests from all companies when Full Multiple Company Support is enabled. This vulnerability impacts Snipe-IT deployments with multiple companies and asset requests, potentially allowing unauthorized access to sensitive asset information. Defenders should assess exposure and prioritize remediation, focusing on verifying company scope filtering and asset request permissions.

Vendor
grokability
Product
snipe-it
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-16
Advisory published
2026-09-09
Advisory updated
2026-09-16

Who should care

Defenders responsible for Snipe-IT deployments with Full Multiple Company Support enabled should assess exposure and prioritize remediation. This includes administrators, security teams, and IT personnel managing asset requests and company scope filtering.

Why it matters

CVE-2026-86767 is a medium-severity vulnerability in Snipe-IT that allows authenticated users to read pending asset requests from all companies when Full Multiple Company Support is enabled. Defenders should prioritize verifying and remediating this vulnerability to prevent unauthorized access to sensitive asset information.

  • Authenticated users can read pending asset requests from all companies
  • Cross-tenant data access without parameter manipulation
  • Potential unauthorized access to sensitive asset information
  • Verification of company scope filtering and asset request permissions required

Technical summary

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled. This allows authenticated users with assets.view permission to read pending asset requests from all companies, including requested asset names, requester display names and profile links, locations, and expected check-in dates. The vulnerability impacts Snipe-IT deployments with multiple companies and asset requests, potentially allowing unauthorized access to sensitive asset information.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability in Snipe-IT deployments with Full Multiple Company Support enabled, especially those with multiple companies and asset requests.

Recommended defensive actions

  • Verify Snipe-IT version and configuration to determine exposure
  • Restrict assets.view permission to prevent unauthorized access
  • Upgrade to Snipe-IT version 8.7.0 or later
  • Monitor asset requests and company scope filtering
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is described in the CVE record and NVD entry. Vendor advisory and third-party advisory sources provide additional context. The CVE record was published on 2026-09-09T14:17:27.133Z and has not been modified since then. Defenders should verify Snipe-IT version and configuration to determine exposure, and review compensating controls for exposed systems while remediation is scheduled and verified.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86767 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86767

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86767 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86767

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-fxm8-w79r-g7wr

    [email protected] - Exploit, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-cross-company-read-via-requested-assets

    [email protected] - Third Party Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.