Improper access control in snipe-it - CVE-2026-54329
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to inject persistent accessory records into another company\'s inventory data.
The vulnerability exists due to improper access control in the Snipe-IT Accessories API create path when handling accessory creation requests with a foreign company_id value. A remote user can submit a crafted API request to inject persistent accessory records into another company\'s inventory data.
Only instances with Full Multiple Companies Support (FMCS) enabled are vulnerable.