Back

HIGH

Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode

Published Aug 19, 2026

Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose personal data and assigned licenses, /users/bulkeditsave can modify out-of-scope profiles, and /users/merge can soft-delete users and transfer assigned assets. This issue is fixed in version 8.6.3.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 19, 2026
Updated Aug 19, 2026
Reserved Jun 16, 2026
CISA Vulnrichment
Updated Aug 19, 2026
NVD
Status Awaiting Analysis
Modified Sep 9, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Aug 19, 2026
Updated Aug 19, 2026
Exploited since n/a
EUVD-2026-62628 GHSA-C6W2-J4WQ-MVWG