Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode
Published Aug 19, 2026
7.6
HIGHCVSS 4.0
EPSS 0.30%
Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/users/{id}/licenses endpoints can expose personal data and assigned licenses, /users/bulkeditsave can modify out-of-scope profiles, and /users/merge can soft-delete users and transfer assigned assets. This issue is fixed in version 8.6.3.
Affected products
-
- Version < 8.6.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Grokability | Snipe-IT | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62628 Advisory
- https://github.com/advisories/GHSA-c6w2-j4wq-mvwg Advisory
- https://github.com/grokability/snipe-it/commit/fbe05a8df4742729a9b0756c016d45f48246cc7b x_refsource_MISC
- https://github.com/grokability/snipe-it/releases/tag/v8.6.3 x_refsource_MISC
- https://github.com/grokability/snipe-it/security/advisories/GHSA-c6w2-j4wq-mvwg x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-55643
Change history (0)
No recorded changes yet.