boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-86747

grokability snipe-it — snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   N    5.3   .0025   14.8     —
AFFECTED
  Product   Versions     Fixed
  snipe-it  unspecified  8.7.0
TIMELINE
  Sep 8   Reserved by VulnCheck
  Sep 9   Published (CNA: VulnCheck)
  Sep 14  EXPLOIT PUBLISHED — CVE-2026-86747 (grokability snipe-it). Public exploit reference added.
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed

Description

Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete (ReportsController::deleteAssetAcceptance) are not correctly scoped when Full Multiple Company Support (FMCS) is enabled. In 8.6.3 the guard ReportsController::currentUserCanAccessAcceptance() early-exits with 'return true' when '! $user->company_id' is truthy, which is the case for every pivot-only user (a user associated with companies through the company_user pivot table whose scalar users.company_id column is NULL); versions prior to 8.6.3 lacked the guard altogether. As a result, an authenticated user holding the reports.view permission can send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the install regardless of which company owns the underlying checkoutable. Deletion is destructive and forfeits the acceptance audit trail for the affected item, and the reminder email exposes limited cross-company acceptance context (item name and assignment metadata) to the recipient. Acceptance IDs are sequential integers and can be enumerated. This issue is fixed in version 8.7.0.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 8, 2026ReservedReserved by VulnCheck
September 9, 2026PublishedPublished (CNA: VulnCheck)
September 14, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-86747 (grokability snipe-it). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
grokabilitysnipe-it——8.7.0

Weaknesses

CWE-863

References (2)

Related

Authoritative record: CVE-2026-86747 at cve.org

Vendors: grokability

Weaknesses: CWE-863

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-86747 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.