High-Risk Authorization Flaw in Snipe-IT Affects Multi-Tenant Deployments

High-Risk Authorization Flaw in Snipe-IT Affects Multi-Tenant Deployments

First seen 10 Sep 2026, 00:44 UTC Redpacketsecuritygithub.com 63.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-86750, has been identified in Snipe-IT versions up to 8.6.3, allowing non-superusers to create or edit user accounts with unauthorized company identifiers via the REST API. This flaw occurs due to a failure to validate company assignment before saving user records, particularly in environments with Full Multiple Companies Support (FMCS). As a result, unauthorized users can gain cross-company visibility and manipulate user accounts across tenant boundaries. The vulnerability is rated as high risk for multi-tenant deployments, especially those accessible over the internet. No active exploitation has been confirmed, but the potential for abuse exists. Users are urged to upgrade to version 8.7.0 or later to mitigate the risk. The vulnerability was published on September 9, 2026, and is particularly concerning for organizations with delegated administrators or federated customer environments.

Key Points: • CVE-2026-86750 allows unauthorized user creation across company boundaries. • Affected versions of Snipe-IT include all prior to 8.7.0. • Immediate upgrade to version 8.7.0 is recommended to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-09
CVE-2026-86750 published
A critical vulnerability in Snipe-IT was disclosed, affecting versions up to 8.6.3.
Redpacketsecurity
2026-09-10
Advisory released on GitHub
GitHub published an advisory detailing the same vulnerability and its implications for user management.
github.com