CVE-2026-55478: Snipe-IT: Missing object-level authorization in Kits API
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kitid}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a license they should not be able to access or manage into a kit. This issue is fixed in version 8.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Snipe-IT Kits APIto a version that resolves this vulnerability.Fixed in 8.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55478?
CVE-2026-55478 has a risk score of 44, indicating a high level of severity.
What type of vulnerability is CVE-2026-55478?
CVE-2026-55478 is a missing object-level authorization vulnerability in the Kits API of Snipe-IT.
How do I fix CVE-2026-55478?
To fix CVE-2026-55478, you should upgrade to Snipe-IT version 8.6.2 or later.
Who is affected by CVE-2026-55478?
Low-privilege users with predefined-kit permissions in Snipe-IT could be affected by CVE-2026-55478.
What functionality is compromised by CVE-2026-55478?
CVE-2026-55478 compromises the authorization checks for binding licenses to kits, allowing unauthorized access.