CVE-2026-55460
- EPSS 0.29%
- Veröffentlicht 10.07.2026 18:39:22
- Zuletzt bearbeitet 14.07.2026 14:16:35
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() ...
CVE-2026-55472
- EPSS 0.2%
- Veröffentlicht 10.07.2026 18:36:58
- Zuletzt bearbeitet 13.07.2026 19:17:13
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return imme...
CVE-2026-55476
- EPSS 0.2%
- Veröffentlicht 10.07.2026 18:35:49
- Zuletzt bearbeitet 13.07.2026 17:17:33
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticate...
CVE-2026-55478
- EPSS 0.18%
- Veröffentlicht 10.07.2026 18:34:15
- Zuletzt bearbeitet 10.07.2026 21:16:56
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefin...
CVE-2026-55843
- EPSS 0.3%
- Veröffentlicht 10.07.2026 18:33:09
- Zuletzt bearbeitet 13.07.2026 16:16:38
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can ove...
CVE-2026-55516
- EPSS 0.22%
- Veröffentlicht 10.07.2026 18:31:57
- Zuletzt bearbeitet 14.07.2026 14:16:35
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id without re-au...
CVE-2026-55474
- EPSS 0.33%
- Veröffentlicht 10.07.2026 18:29:56
- Zuletzt bearbeitet 10.07.2026 20:16:47
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse out...
CVE-2026-54329
- EPSS 0.23%
- Veröffentlicht 10.07.2026 18:26:44
- Zuletzt bearbeitet 10.07.2026 21:16:55
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company...
CVE-2026-48492
- EPSS 0.23%
- Veröffentlicht 08.07.2026 21:11:19
- Zuletzt bearbeitet 10.07.2026 19:46:50
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated l...
CVE-2026-55542
- EPSS 0.17%
- Veröffentlicht 08.07.2026 20:32:14
- Zuletzt bearbeitet 10.07.2026 19:48:18
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minu...