CyberRota Analysis
AI-GeneratedSnipe-IT versions up to 8.6.3 are vulnerable due to inadequate authorization checks in the REST API, allowing non-superuser accounts with specific permissions to assign users to unauthorized companies. This flaw can lead to unauthorized user account creation or relocation across tenant boundaries, potentially exposing sensitive data and compromising multi-tenant environments. Organizations using Snipe-IT with Full Multiple Companies Support should prioritize upgrading to version 8.7.0 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and saved before the requested company_id / company_ids[] values are filtered against the actor's permitted companies (Company::getIdsForCurrentUser()). On installs using Full Multiple Companies Support (FMCS), a non-superuser holding users.create (or users.edit on a target user) can submit company identifiers for companies outside their scope — including a mix of permitted and foreign ids — causing the account row to be committed to the database before authorization is checked. Where null_company_is_floater=1 is set, the post-hoc filter leaves an empty company pivot and the account is persisted as a "floater" with cross-company visibility, allowing creation or relocation of user accounts across tenant boundaries.
Related CVEs
Other vulnerabilities affecting the same vendor(s)