CVE-2026-55515
EUVD-2026-4299510.07.2026, 20:16
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to delete pending checkout acceptance records for another company. This issue is fixed in version 8.6.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| snipeitapp | snipe-it | 𝑥 < 8.6.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References