Medium severity5.4NVD Advisory· Published Aug 19, 2026· Updated Sep 9, 2026
CVE-2026-55519
CVE-2026-55519
Description
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesController.php and app/Http/Controllers/UploadedFilesController.php authorize update against the object class instead of the resolved object instance, creating an insecure direct object reference. This issue is fixed in version 8.4.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snipe/snipe-itPackagist | < 8.4.1 | 8.4.1 |
Affected products
2- Range: <=8.4.0
- Range: <8.4.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.