← Browse

CVE-2026-85616

Medium

Elevated severity or exploit probability.

CVSS base
8.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
EPSS — probability of exploitation (30 days)
0.2%
16.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-639
Published 2026-09-04 · modified 2026-09-16

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionNNone
ScopeCChanged
ConfidentialityNNone
IntegrityHHigh
AvailabilityLLow

Timeline

Description

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column.

Affected

snipeitapp

References

Official: NVD · CVE.org