Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54329

Опубликовано: 10 июл. 2026
Источник: debian
EPSS Низкий

Описание

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
snipe-ititppackage

EPSS

Процентиль: 13%
0.00225
Низкий

Связанные уязвимости

CVSS3: 8.5
nvd
28 дней назад

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.

CVSS3: 8.5
github
около 2 месяцев назад

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

EPSS

Процентиль: 13%
0.00225
Низкий