High-Risk Authorization Flaw in Snipe-IT Affects Multi-Tenant Deployments
Article Content
A critical vulnerability, CVE-2026-86750, has been identified in Snipe-IT versions up to 8.6.3, allowing non-superusers to create or edit user accounts with unauthorized company identifiers via the REST API. This flaw occurs due to a failure to validate company assignment before saving user records, particularly in environments with Full Multiple Companies Support (FMCS). As a result, unauthorized users can gain cross-company visibility and manipulate user accounts across tenant boundaries. The vulnerability is rated as high risk for multi-tenant deployments, especially those accessible over the internet. No active exploitation has been confirmed, but the potential for abuse exists. Users are urged to upgrade to version 8.7.0 or later to mitigate the risk. The vulnerability was published on September 9, 2026, and is particularly concerning for organizations with delegated administrators or federated customer environments.
Key Points: • CVE-2026-86750 allows unauthorized user creation across company boundaries. • Affected versions of Snipe-IT include all prior to 8.7.0. • Immediate upgrade to version 8.7.0 is recommended to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.