PT-2026-78575 · Snipe-It · Snipe-It
CVE-2026-55643
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.6.3
Description
An issue exists where a company-scoped user in FMCS floater mode can access users with a null
company id because the isCurrentUserHasAccess check is not consistently applied during broad API queries and bulk web actions. This allows for the exposure of personal data and assigned licenses via the '/api/v1/users' and '/api/v1/users/{id}/licenses' endpoints. Additionally, the '/users/bulkeditsave' endpoint can be used to modify profiles outside the user's scope, and the '/users/merge' endpoint can be used to transfer assigned assets and soft-delete users.Recommendations
Update to version 8.6.3.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It