Junglewise Threat Intelligence

CVE-2026-55479: Grokability Snipe-IT incorrect authorization in legacy license checkin

CVE-2026-55479 · Severity: medium · CVSS 4 · Published 2026-07-10

Technologies: Grokability Snipe-It, snipe/snipe-it (Packagist). Vendors: Packagist.

Executive brief

Snipe-IT is an asset management system used to track and assign software licenses to users and devices. A flaw in its legacy license checkin API permits users with limited license assignment permissions to bypass restrictions and reclaim licenses that are already assigned to others, potentially disrupting license compliance and asset assignments within an organization.

Technical details

The vulnerability is an incorrect authorization flaw (CWE-863) in Snipe-IT's legacy single-seat license checkin flow. The endpoint checks for the "checkout" permission when it should check for "checkin" permission, allowing privilege escalation. An authenticated user with license assignment rights but without unassignment rights can directly access the old checkin endpoint to reclaim license seats from other users or assets. The attack requires network access and a low-privileged authenticated account; no user interaction is needed. The vulnerability is fixed in version 8.6.2.

Affected products

  • Grokability Snipe-IT <= 8.6.1

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: patched: Version 8.6.2 released
  • 2026-07-10: advisory
  • 2026-08-28: advisory: Updated on GitHub Advisory Database

References

Related threats