Incorrect Authorization Affecting snipe/snipe-it package, versions <8.7.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-SNIPESNIPEIT-20079172
  • published24 Sept 2026
  • disclosed10 Sept 2026
  • creditUnknown

Introduced: 10 Sep 2026

NewCVE-2026-88894  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade snipe/snipe-it to version 8.7.2 or higher.

Overview

snipe/snipe-it is an asset management system built on Laravel.

Affected versions of this package are vulnerable to Incorrect Authorization in the PredefinedKitCheckoutService process. An attacker can assign assets, licenses, consumables, or accessories from one company to a user in another company by sending a crafted POST request to /kits/{kit}/checkout when Full Multiple Company Support (FMCS) is enabled and the attacker is a non-superuser belonging to at least two companies with the assets.checkout permission. This is only exploitable if FMCS is enabled and the attacker meets the multi-company and permission requirements.

References

CVSS Base Scores

version 4.0
version 3.1