Improper access control in snipe-it - CVE-2026-55515

 

Improper access control in snipe-it - CVE-2026-55515

Published: August 14, 2026


Vulnerability identifier: #VU142572
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55515
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete pending checkout acceptance records across company boundaries.

The vulnerability exists due to improper access control in the unaccepted assets report delete endpoint when handling deletion requests by global acceptance ID. A remote user can send a specially crafted request to delete pending checkout acceptance records across company boundaries.

Exploitation requires a valid authenticated web session, the reports.view permission, and knowledge or guessability of a pending checkout_acceptances.id. The issue affects multi-company mode.


Affected software

snipe-it

How to mitigate CVE-2026-55515

Install security update from vendor's website.

snipe-it - update to 8.6.2

External References

Related Security Bulletins