---
id: CVE-2026-85616
title: >-
  Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability
  in checkout-acceptance report actions when Full Multiple Company Support is
  enabled
summary: >-
  Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability
  in checkout-acceptance report actions when Full Multiple Company Support is
  enabled. Authenticated users with reports.view permission can enumerate
  sequential a…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'
cwe:
  - CWE-639
vendor: snipeitapp
product: snipe-it
affected:
  - snipe-it < 8.6.2
patched:
  - snipe-it 8.6.2
published: '2026-09-04'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:42:07.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85616'
references:
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-jqgw-vpjc-86fc
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/snipe-it-before-8.6.2-authorization-bypass-via-checkout-acceptance
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-jqgw-vpjc-86fc
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00247
epssPercentile: 0.1625
ingestedAt: '2026-09-08T21:11:12.294Z'
---

## Overview

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column.

## Affected

- `snipe-it < 8.6.2`

## Remediation

Upgrade past the affected range:

- `snipe-it 8.6.2`
