{"id":"CVE-2026-55478","aliases":["GHSA-crv3-j83j-f3r6"],"url":"https://o3.security/vulnerability/CVE-2026-55478","summary":"Snipe-IT: Missing object-level authorization in Kits API","details":"Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a license they should not be able to access or manage into a kit. This issue is fixed in version 8.6.2.","published":"2026-07-10T18:34:15.757Z","modified":"2026-08-27T03:57:10.715850629Z","cvss":null,"epss":{"score":0.00294,"percentile":0.21373,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"snipe/snipe-it","fixedVersion":"8.6.2"}],"fix":{"url":"https://github.com/grokability/snipe-it/commit/0d870d540d27107634f3134e0e7f106b3faa6992","label":"grokability/snipe-it@0d870d5"},"references":[{"type":"WEB","url":"https://github.com/grokability/snipe-it/releases/tag/v8.6.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55478.json"},{"type":"ADVISORY","url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-crv3-j83j-f3r6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55478"},{"type":"FIX","url":"https://github.com/grokability/snipe-it/commit/0d870d540d27107634f3134e0e7f106b3faa6992"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:57:10.715850629Z"}}