Количество 3
Количество 3
CVE-2026-55843
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an administrator updating another administrator, or a user with users.edit updating a regular account, to remove the target’s administrative or granular permissions. This issue is fixed in version 8.6.0.
CVE-2026-55843
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, Use ...
GHSA-j5g3-42wp-gqm3
Snipe-IT has an Improper Privilege Management issue
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55843 Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an administrator updating another administrator, or a user with users.edit updating a regular account, to remove the target’s administrative or granular permissions. This issue is fixed in version 8.6.0. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-55843 Snipe-IT is an IT asset/license management system. Prior to 8.6.0, Use ... | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
GHSA-j5g3-42wp-gqm3 Snipe-IT has an Improper Privilege Management issue | CVSS3: 6.5 | 1% Низкий | 25 дней назад |
Уязвимостей на страницу