Privilege Escalation Vulnerability in Snipe-IT by Grokability
CVE-2026-55483
4.9MEDIUM
What is CVE-2026-55483?
A privilege escalation vulnerability exists in Snipe-IT, an IT asset management system, allowing authenticated users with 'users.create' permissions to assign themselves admin permissions when creating new user accounts. Despite the system's capability to strip superuser permissions, it improperly retains admin rights, enabling unauthorized access to administrative features. This vulnerability was addressed in version 8.6.0, emphasizing the need for users to upgrade to maintain security.
Affected Version(s)
snipe-it < 8.6.0
