SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85616

HIGH · CVSS 8.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Versions of Snipe-IT prior to 8.6.2 are susceptible to an authorization bypass vulnerability that allows authenticated users with the reports.view permission to access and manipulate acceptance records across different companies. This can lead to unauthorized soft-deletion of records and the triggering of reminder emails, potentially compromising data integrity and confidentiality. Organizations using Snipe-IT with Full Multiple Company Support enabled should prioritize applying the latest update to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85616
Severity
HIGH
CVSS
8.5
EPSS
0.27%

Original NVD Description

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column.

Related CVEs

Other vulnerabilities affecting the same vendor(s)