Vulnerability in Snipe-IT IT Asset Management System
CVE-2026-50550
5.8MEDIUM
What is CVE-2026-50550?
Snipe-IT, an IT asset and license management system, has a vulnerability that allows users with edit permissions to bypass authorization controls. This issue, present in versions up to 8.5.0, enables such users to reset a superadmin's two-factor authentication settings without proper permissions. The affected endpoint incorrectly authorizes access for resetting two-factor credentials, thereby exposing sensitive administrative functions to potential misuse. The issue has been resolved in version 8.5.0.
Affected Version(s)
snipe-it < 8.5.0
