CVE-2026-55643

HIGH CVSS 4.0: 7.6 EPSS 0.26%
Updated Sep 10, 2026
Snipe-It
Parameter Value
CVSS 7.6 (HIGH)
Fixed In 8.6.3
Type CWE-863 (Incorrect Authorization)
Vendor Snipe-It
Public PoC No

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose personal data and assigned licenses, /users/bulkeditsave can modify out-of-scope profiles, and /users/merge can soft-delete users and transfer assigned assets.

This issue is fixed in version 8.6.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Related Vulnerabilities