CVE-2026-55476Medium▾ SunlitSnipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
The route POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a plain URL path segment with no authorization check. Any authenticated user regardless of permissions can set this parameter to a truthy value and supply a victim's user ID to silently cancel that user's pending asset requests. The attacker only needs an active session; no elevated privilege is required.
Patched in 8.6.1
snipe/snipe-it < 8.6.0Upgrade to a patched release:
snipe/snipe-it 8.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55483MediumSnipe-IT is an IT asset/license management system
CVE-2026-55843High· 6.5Snipe-IT has an Improper Privilege Management issue
CVE-2026-55703Medium· 4.3Snipe-IT is an IT asset/license management system
CVE-2026-48492MediumSnipe-IT's selectlist visibility is too permissive
CVE-2026-49976Medium· 6.5Snipe-IT is an IT asset/license management system
CVE-2026-50550Medium· 5.8Snipe-IT is an IT asset/license management system