Количество 3
Количество 3
CVE-2026-55479
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another user or asset. This issue is fixed in version 8.6.2.
CVE-2026-55479
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ...
GHSA-8frh-vhgh-64cf
Snipe-IT has incorrect permission for legacy license checkin API
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55479 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another user or asset. This issue is fixed in version 8.6.2. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-55479 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the ... | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-8frh-vhgh-64cf Snipe-IT has incorrect permission for legacy license checkin API | 0% Низкий | 26 дней назад |
Уязвимостей на страницу