High severity8.8NVD Advisory· Published Aug 19, 2026· Updated Sep 30, 2026
CVE-2026-55643
CVE-2026-55643
Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose personal data and assigned licenses, /users/bulkeditsave can modify out-of-scope profiles, and /users/merge can soft-delete users and transfer assigned assets. This issue is fixed in version 8.6.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snipe/snipe-itPackagist | < 8.6.3 | 8.6.3 |
Affected products
3- Range: <8.6.3
Patches
Vulnerability mechanics
References
5- github.com/grokability/snipe-it/commit/fbe05a8df4742729a9b0756c016d45f48246cc7bnvdPatchWEB
- github.com/grokability/snipe-it/releases/tag/v8.6.3nvdRelease NotesPatchWEB
- github.com/grokability/snipe-it/security/advisories/GHSA-c6w2-j4wq-mvwgnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-c6w2-j4wq-mvwgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55643ghsaADVISORY
News mentions
0No linked articles in our index yet.