VYPR
Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 13, 2026

Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint

CVE-2026-55515

Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to delete pending checkout acceptance records for another company. This issue is fixed in version 8.6.2.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.