CVE-2026-55482Medium· 6.3▾ SunlitSnipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing asse…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to be moved across company boundaries and breaking multi-tenant isolation. This issue is fixed in version 8.4.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
snipe/snipe-it <= 8.4.1Patched in:
snipe/snipe-it 8.4.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55516High· 7.7Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
CVE-2026-55694HighSnipe-IT is an IT asset/license management system
CVE-2026-55519Medium· 5.4Snipe-IT is an IT asset/license management system
CVE-2026-55843High· 6.5Snipe-IT has an Improper Privilege Management issue
CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users
CVE-2026-55464Medium· 5.4Snipe-IT vulnerable to stored XSS via Markdown custom field