8.5
CVE-2026-54329
- EPSS 0.23%
- Veröffentlicht 10.07.2026 18:26:44
- Zuletzt bearbeitet 10.07.2026 21:16:55
- CVE-Watchlists
- Unerledigt
Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Snipeitapp ≫ Snipe-it Version < 8.6.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.133 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
|
| security-advisories@github.com | 8.5 | 3.1 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/grokability/snipe-it/security/advisories/GHSA-pwpj-p52h-q484
https://github.com/grokability/snipe-it/commit/6a0ec6945126a79fc25c0990c99abe632db370c3
https://github.com/grokability/snipe-it/commit/dc8cbf4786bb38b260b4ae1723ec9e7f81d82fe5
https://github.com/grokability/snipe-it/commit/e2bea57146eb3a3781b5eb21b69d7e04cc87c268
https://github.com/grokability/snipe-it/releases/tag/v8.6.2