CVE-2026-86767

⚪ Do wiadomości

Brak filtrowania zakresu w Snipe-IT pozwala na odczytanie danych z innych firm przez uwierzytelnionych użytkowników.

CVSS
5.0
EPSS
0.2%
Exploit
poc
Vendor
snipeitapp
Opis źródłowy (NVD)

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can retrieve cross-tenant data including requested asset names, requester display names and profile links, locations, and expected check-in dates without parameter manipulation.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-09 14:17:27 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:28:24 UTC
Referencje