Vulnerability in Snipe-IT Asset Management System Allows Unauthorized Asset Movement
CVE-2026-55482
6.3MEDIUM
What is CVE-2026-55482?
A critical vulnerability in Snipe-IT, an IT asset and license management system, allows non-superadmin users to manipulate company IDs using the update method in the BulkAssetsController.php file. This flaw enables unauthorized asset transfers across different company boundaries, violating the principles of multi-tenant data isolation. The vulnerability has been remedied in version 8.4.1, ensuring that only authorized users can manage assets within their respective organizational boundaries.
Affected Version(s)
snipe-it < 8.4.1
