Unauthorized Data Access in Snipe-IT IT Asset Management System
CVE-2026-55643
7.6HIGH
What is CVE-2026-55643?
The Snipe-IT IT asset and license management system contains an authorization bypass vulnerability that allows users with company-scoped access in FMCS floater mode to gain unauthorized access to other users whose 'company_id' is null. This exploit can enable attackers to make broad API queries and perform bulk web actions without consistent authorization checks. As a result, sensitive personal data and assigned licenses via the /api/v1/users endpoints can be exposed, and unauthorized modifications or deletions of user profiles may occur through endpoints such as /users/bulkeditsave and /users/merge. The issue has been resolved in version 8.6.3.
Affected Version(s)
snipe-it < 8.6.3
