CVE-2026-55519Medium· 5.4▾ SunlitSnipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
0.2% → 0.2%
Last analysed / modified upstream
5.4 → —
medium → low
— → 5.4
low → medium
5.4 → —
medium → low
— → 5.4
low → medium
5.4 → —
medium → low
— → 5.4
low → medium
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesController.php and app/Http/Controllers/UploadedFilesController.php authorize update against the object class instead of the resolved object instance, creating an insecure direct object reference. This issue is fixed in version 8.4.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
snipe/snipe-it <= 8.4.0Patched in:
snipe/snipe-it 8.4.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55482Medium· 6.3Snipe-IT is an IT asset/license management system
CVE-2026-55843High· 6.5Snipe-IT has an Improper Privilege Management issue
CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users
CVE-2026-55464Medium· 5.4Snipe-IT vulnerable to stored XSS via Markdown custom field
CVE-2026-55472Medium· 4.3Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
CVE-2026-55476MediumSnipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter