PT-2026-78575 · Snipe-It · Snipe-It

CVE-2026-55643

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.6.3
Description An issue exists where a company-scoped user in FMCS floater mode can access users with a null company id because the isCurrentUserHasAccess check is not consistently applied during broad API queries and bulk web actions. This allows for the exposure of personal data and assigned licenses via the '/api/v1/users' and '/api/v1/users/{id}/licenses' endpoints. Additionally, the '/users/bulkeditsave' endpoint can be used to modify profiles outside the user's scope, and the '/users/merge' endpoint can be used to transfer assigned assets and soft-delete users.
Recommendations Update to version 8.6.3.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55643
GHSA-C6W2-J4WQ-MVWG

Affected Products

Snipe-It