CVE-2026-86747 | Grokability Snipe-IT up to 8.6.3 ReportsController sent_reminder currentUserCanAccessAcceptance acceptanceId permission
A vulnerability identified as critical has been detected in Grokability Snipe-IT up to 8.6.3. Impacted is the function ReportsController::currentUserCanAccessAcceptance of the file /reports/unaccepted_assets/sent_reminder of the component ReportsController. This manipulation of the argument acceptanceId causes permission issues.
This vulnerability is registered as CVE-2026-86747. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More