CVE-2026-86750 | Grokability Snipe-IT up to 8.6.3 REST API store company_id/company_ids improper authorization
A vulnerability was found in Grokability Snipe-IT up to 8.6.3. It has been declared as problematic. This affects the function ApiUsersController::store of the component REST API. Such manipulation of the argument company_id/company_ids leads to improper authorization.
This vulnerability is referenced as CVE-2026-86750. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More