CVE-2026-55843 Details
Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an administrator updating another administrator, or a user with users.edit updating a regular account, to remove the target’s administrative or granular permissions. This issue is fixed in version 8.6.0.
A vulnerability exists in Snipe-IT versions prior to 8.6.0, specifically within the UsersController's update method. The issue arises because the method passes a missing permission request field through two actions in a way that can unintentionally overwrite a user's permissions. This allows an administrator to update another administrator's account, or a user with the 'users.edit' permission to update a regular account, and remove critical permissions such as administrative rights or specific granular permissions. The vulnerability is rooted in improper handling of permission fields during user updates, which can lead to significant unintentional changes in user roles and capabilities.
Users are advised to upgrade to Snipe-IT version 8.6.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| snipeitapp snipe-it | < 8.6.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | New CVE Received | [email protected] |