CVE-2026-55643
- EPSS 0.26%
- Veröffentlicht 19.08.2026 18:25:39
- Zuletzt bearbeitet 30.09.2026 12:58:41
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. T...
CVE-2026-55703
- EPSS 0.19%
- Veröffentlicht 19.08.2026 18:23:43
- Zuletzt bearbeitet 30.09.2026 12:50:06
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/Maintena...
CVE-2026-61807
- EPSS 0.28%
- Veröffentlicht 19.08.2026 18:22:21
- Zuletzt bearbeitet 30.09.2026 12:49:27
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads...
CVE-2026-55519
- EPSS 0.21%
- Veröffentlicht 19.08.2026 18:20:14
- Zuletzt bearbeitet 30.09.2026 12:58:58
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Cont...
CVE-2026-55482
- EPSS 0.19%
- Veröffentlicht 19.08.2026 18:18:35
- Zuletzt bearbeitet 30.09.2026 12:59:15
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to be move...
CVE-2026-55483
- EPSS 0.3%
- Veröffentlicht 19.08.2026 18:17:11
- Zuletzt bearbeitet 30.09.2026 12:59:07
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php strips super...
CVE-2026-50550
- EPSS 0.18%
- Veröffentlicht 19.08.2026 18:15:44
- Zuletzt bearbeitet 30.09.2026 12:59:24
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint authorizes u...
CVE-2026-49870
- EPSS 0.31%
- Veröffentlicht 19.08.2026 18:13:05
- Zuletzt bearbeitet 30.09.2026 13:00:08
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes creat...
CVE-2026-49976
- EPSS 0.34%
- Veröffentlicht 19.08.2026 18:11:48
- Zuletzt bearbeitet 30.09.2026 12:59:56
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. app/Importer/...
CVE-2026-19579
- EPSS 0.24%
- Veröffentlicht 11.08.2026 20:25:02
- Zuletzt bearbeitet 21.08.2026 19:22:51
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used with...