Unauthorized Data Access in Snipe-IT IT Asset Management System
CVE-2026-55643

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55643?

The Snipe-IT IT asset and license management system contains an authorization bypass vulnerability that allows users with company-scoped access in FMCS floater mode to gain unauthorized access to other users whose 'company_id' is null. This exploit can enable attackers to make broad API queries and perform bulk web actions without consistent authorization checks. As a result, sensitive personal data and assigned licenses via the /api/v1/users endpoints can be exposed, and unauthorized modifications or deletions of user profiles may occur through endpoints such as /users/bulkeditsave and /users/merge. The issue has been resolved in version 8.6.3.

Affected Version(s)

snipe-it < 8.6.3

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.