CVE-2026-55479: Snipe-IT: Incorrect permission for legacy license checkin API
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another user or asset. This issue is fixed in version 8.6.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55479?
CVE-2026-55479 has a medium severity rating of 5.3 based on the CVSS score.
How do I fix CVE-2026-55479?
To fix CVE-2026-55479, upgrade your Snipe-IT instance to version 8.6.2 or later.
What is the impact of CVE-2026-55479?
CVE-2026-55479 allows unauthorized users to access legacy license checkin functionality, potentially misusing license assignments.
Which versions of Snipe-IT are affected by CVE-2026-55479?
CVE-2026-55479 affects all versions of Snipe-IT prior to 8.6.2.
Is there a workaround for CVE-2026-55479 before upgrading?
There are no known workarounds for CVE-2026-55479; upgrading to the patched version is recommended.