CyberRota Analysis
AI-GeneratedVersions of Snipe-IT prior to 8.6.2 are susceptible to an authorization bypass vulnerability that allows authenticated users with the reports.view permission to access and manipulate acceptance records across different companies. This can lead to unauthorized soft-deletion of records and the triggering of reminder emails, potentially compromising data integrity and confidentiality. Organizations using Snipe-IT with Full Multiple Company Support enabled should prioritize applying the latest update to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column.
Related CVEs
Other vulnerabilities affecting the same vendor(s)