SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-55643

HIGH · CVSS 7.6 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Snipe-IT versions prior to 8.6.3 are vulnerable to unauthorized access, allowing company-scoped users in FMCS floater mode to access user data with a null company_id due to inconsistent access controls in API queries. This vulnerability can lead to exposure of personal data, unauthorized modifications of user profiles, and improper asset transfers. Organizations using Snipe-IT should prioritize upgrading to version 8.6.3 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55643
Severity
HIGH
CVSS
7.6
EPSS
0.26%

Original NVD Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose personal data and assigned licenses, /users/bulkeditsave can modify out-of-scope profiles, and /users/merge can soft-delete users and transfer assigned assets. This issue is fixed in version 8.6.3.