🚨 CVE-2026-85616
Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column.
🎖@cveNotify

GitHub
FMCS Bypass on Checkout-Acceptance Report Actions (Cross-Company Delete + Reminder Send)
When Full Multiple Company Support (FMCS) was enabled, two checkout-acceptance report actions read the legacy scalar `users.company_id` column to decide whether the caller was allowed to touch a sp...
September 4, 2026 63