CVE-2026-55482: Snipeitapp Snipe-It

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to be moved across company boundaries and breaking multi-tenant isolation. This issue is fixed in version 8.4.1.

Affected products

  • Snipeitapp Snipe-It: before 8.4.1 (fixed in 8.4.1)

Published 2026-08-19. Last modified 2026-09-30.