Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88894— Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout

Quick assessment

Affected
grokability snipe-it
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Snipe-IT 中预定义套件(Predefined Kit)的签出路径未在签出目标处强制执行“完整多公司支持”(FMCS)的租户隔离。与单一物品、批量、API、配件、许可证及耗材的签出路径不同, 从未调用 方法;它仅在执行签出持久化之前,执行了“操作者 vs 物品”的策略检查和可用性检查。 在启用 FMCS 的情况下,一个非超级用户如果同时属于至少两家公司,并拥有 权限,就可以向 发起 POST 请求,将一个仅属于 B 公司的用户 ID 作为签出目标,从而将 A 公司的资产(以及相应的套件许可证、耗材和配件)分配

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88894

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout
Source: CVE Program / CVE List V5
Vulnerability Description
Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls $item->canCheckoutTo($target); it only performs the actor-vs-item policy check and an availability check before persisting the checkout. With FMCS enabled, a non-superuser who belongs to at least two companies and holds the assets.checkout permission can POST to /kits/{kit}/checkout with a user_id belonging only to company B and have a company-A asset (and likewise kit licenses, consumables and accessories) assigned to that user, bypassing the company-mismatch check that blocks the same operation on every other checkout path. The issue is fixed in Snipe-IT 8.7.2; it was runtime-verified on v8.6.3 and code-inspected on v8.7.1, and the affected service has lacked the check since 2019, so earlier FMCS deployments are likely also affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
grokability snipe-it 0 ~ 8.7.2 -

II. Public POCs for CVE-2026-88894

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88894

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88894 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-88894

No comments yet


Leave a comment