Privilege Escalation in Snipe-IT IT Asset Management System
CVE-2026-44832
7.1HIGH
What is CVE-2026-44832?
A privilege escalation vulnerability exists in the Snipe-IT IT asset and license management system. An authenticated user with limited permissions can exploit the API to elevate their access rights to admin level by manipulating the permissions array with a PATCH request. This flaw stems from insufficient checks in the API controller, allowing users to set admin permissions indiscriminately. The issue has been addressed in version 8.4.1, emphasizing the need for users to update their installations to maintain security.
Affected Version(s)
snipe-it < 8.4.1
