PatchSiren cyber security CVE debrief
CVE-2026-86767 grokability CVE debrief
CVE-2026-86767 is a vulnerability in Snipe-IT versions before 8.7.0 that allows authenticated users with assets.view permission to read pending asset requests from all companies when Full Multiple Company Support is enabled. This vulnerability impacts Snipe-IT deployments with multiple companies and asset requests, potentially allowing unauthorized access to sensitive asset information. Defenders should assess exposure and prioritize remediation, focusing on verifying company scope filtering and asset request permissions.
- Vendor
- grokability
- Product
- snipe-it
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-16
Who should care
Defenders responsible for Snipe-IT deployments with Full Multiple Company Support enabled should assess exposure and prioritize remediation. This includes administrators, security teams, and IT personnel managing asset requests and company scope filtering.
Why it matters
CVE-2026-86767 is a medium-severity vulnerability in Snipe-IT that allows authenticated users to read pending asset requests from all companies when Full Multiple Company Support is enabled. Defenders should prioritize verifying and remediating this vulnerability to prevent unauthorized access to sensitive asset information.
- Authenticated users can read pending asset requests from all companies
- Cross-tenant data access without parameter manipulation
- Potential unauthorized access to sensitive asset information
- Verification of company scope filtering and asset request permissions required
Technical summary
Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled. This allows authenticated users with assets.view permission to read pending asset requests from all companies, including requested asset names, requester display names and profile links, locations, and expected check-in dates. The vulnerability impacts Snipe-IT deployments with multiple companies and asset requests, potentially allowing unauthorized access to sensitive asset information.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in Snipe-IT deployments with Full Multiple Company Support enabled, especially those with multiple companies and asset requests.
Recommended defensive actions
- Verify Snipe-IT version and configuration to determine exposure
- Restrict assets.view permission to prevent unauthorized access
- Upgrade to Snipe-IT version 8.7.0 or later
- Monitor asset requests and company scope filtering
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is described in the CVE record and NVD entry. Vendor advisory and third-party advisory sources provide additional context. The CVE record was published on 2026-09-09T14:17:27.133Z and has not been modified since then. Defenders should verify Snipe-IT version and configuration to determine exposure, and review compensating controls for exposed systems while remediation is scheduled and verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86767 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86767
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86767 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86767
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-fxm8-w79r-g7wr
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-cross-company-read-via-requested-assets
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.