Количество 3
Количество 3
CVE-2026-54329
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.
CVE-2026-54329
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ...
GHSA-pwpj-p52h-q484
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-54329 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2. | CVSS3: 8.5 | 0% Низкий | 29 дней назад | |
CVE-2026-54329 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ... | CVSS3: 8.5 | 0% Низкий | 29 дней назад | |
GHSA-pwpj-p52h-q484 Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection | CVSS3: 8.5 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу