Junglewise Threat Intelligence

CVE-2026-55478: grokability Snipe-IT missing object-level authorization in Kits API

CVE-2026-55478 · Severity: medium · CVSS 5.3 · Published 2026-07-10

Technologies: snipe/snipe-it (Packagist), Snipe-It. Vendors: Packagist.

Executive brief

Snipe-IT is an open-source asset management platform that tracks hardware, software, and licenses. A flaw in its Kits API allows low-privilege users with kit management permissions to attach licenses they shouldn't have access to, bypassing license-level access controls. This could lead to unauthorized data exposure or mismanagement of restricted software licenses.

Technical details

The POST /api/v1/kits/{kit_id}/licenses API endpoint in Snipe-IT performs authorization checks only at the kit level, verifying that the caller can edit kits, but fails to validate object-level authorization on the license being added. This is a CWE-639 authorization bypass vulnerability: an attacker with limited kit-management permissions can link any license to a kit, regardless of their permissions on that specific license. The attack vector is network-based and requires low-level authentication (kit edit privileges). No user interaction is needed. An attacker can gain unauthorized access to or modify license metadata and associations. The vulnerability affects versions 8.6.1 and earlier; patch 8.6.2 is available.

Affected products

  • Snipe-IT Snipe-IT <= 8.6.1

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: patched: Patch v8.6.2 released
  • 2026-07-10: advisory: Published to NVD
  • 2026-08-28: advisory: Published to GitHub Advisory Database

References

Related threats