Improper access control in snipe-it - CVE-2026-55515
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to delete pending checkout acceptance records across company boundaries.
The vulnerability exists due to improper access control in the unaccepted assets report delete endpoint when handling deletion requests by global acceptance ID. A remote user can send a specially crafted request to delete pending checkout acceptance records across company boundaries.
Exploitation requires a valid authenticated web session, the reports.view permission, and knowledge or guessability of a pending checkout_acceptances.id. The issue affects multi-company mode.