SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-86750

HIGH · CVSS 7.7 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Snipe-IT versions up to 8.6.3 are vulnerable due to inadequate authorization checks in the REST API, allowing non-superuser accounts with specific permissions to assign users to unauthorized companies. This flaw can lead to unauthorized user account creation or relocation across tenant boundaries, potentially exposing sensitive data and compromising multi-tenant environments. Organizations using Snipe-IT with Full Multiple Companies Support should prioritize upgrading to version 8.7.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86750
Severity
HIGH
CVSS
7.7
EPSS
0.18%

Original NVD Description

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and saved before the requested company_id / company_ids[] values are filtered against the actor's permitted companies (Company::getIdsForCurrentUser()). On installs using Full Multiple Companies Support (FMCS), a non-superuser holding users.create (or users.edit on a target user) can submit company identifiers for companies outside their scope — including a mix of permitted and foreign ids — causing the account row to be committed to the database before authorization is checked. Where null_company_is_floater=1 is set, the post-hoc filter leaves an empty company pivot and the account is persisted as a "floater" with cross-company visibility, allowing creation or relocation of user accounts across tenant boundaries.

Related CVEs

Other vulnerabilities affecting the same vendor(s)