Junglewise Threat Intelligence

CVE-2026-55482: Grokability Snipe-IT multi-tenancy bypass in Bulk Asset Update

CVE-2026-55482 · Severity: medium · CVSS 6.3 · Published 2026-06-23

Technologies: Grokability Snipe-It, snipe/snipe-it (Packagist). Vendors: Packagist.

Executive brief

Snipe-IT, an open-source IT asset management system, contains a flaw that allows users to bypass multi-tenancy restrictions. In environments where multiple companies share the same system, a regular user can move assets between different companies. This could lead to unauthorized access to asset records and disruption of inventory management across different business units or clients.

Technical details

An authorization bypass (CWE-639) exists in the BulkAssetsController::update() method of Snipe-IT. The vulnerability stems from the application accepting a 'company_id' directly from user input without validating it against the standard company-scoping function 'Company::getIdForCurrentUser()'. An authenticated attacker with low privileges can exploit this to reassign assets to different companies, breaking the isolation intended in multi-tenant deployments. The issue is addressed in version 8.4.2 by ensuring proper company-scoping checks are applied during bulk updates.

Affected products

  • Grokability Snipe-IT <= 8.4.1

Timeline

  • 2026-06-12: disclosed: Vulnerability reported and patched in repository
  • 2026-06-23: advisory: GitHub Advisory published

References

Related threats