Количество 3
Количество 3
CVE-2026-55472
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2.
CVE-2026-55472
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, whe ...
GHSA-8w8c-8mx9-52cw
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55472 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-55472 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, whe ... | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-8w8c-8mx9-52cw Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation | CVSS3: 4.3 | 0% Низкий | 26 дней назад |
Уязвимостей на страницу