Improper access control in snipe-it - CVE-2026-55643
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to bypass tenant isolation to read, modify, and soft-delete out-of-scope user records.
The vulnerability exists due to improper access control in multiple API endpoints and bulk action web routes when handling company-scoped user operations. A remote user can access and manipulate users with company_id = null to bypass tenant isolation to read, modify, and soft-delete out-of-scope user records.
The issue affects floater mode and exposed data can include personally identifiable information, assigned licenses, and transferred assigned assets.