CVE-2026-55516: Snipe-IT: Cross-company asset maintenance re-parenting via API update
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenanceid} checks access to the current maintenance record and asset but then fills attacker-controlled fields including assetid without re-authorizing the newly supplied asset, allowing an authorized user to move a maintenance record onto an asset outside their company scope. This issue is fixed in version 8.6.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55516?
CVE-2026-55516 has a severity rating of high, with a score of 7.7.
How do I fix CVE-2026-55516?
To fix CVE-2026-55516, upgrade Snipe-IT to version 8.6.2 or later.
What systems are affected by CVE-2026-55516?
CVE-2026-55516 affects Snipe-IT versions prior to 8.6.2.
What type of vulnerability is CVE-2026-55516?
CVE-2026-55516 is a cross-company asset maintenance re-parenting vulnerability via API update.
Can CVE-2026-55516 lead to unauthorized access?
Yes, CVE-2026-55516 can allow attackers to exploit the vulnerability and manipulate asset maintenance records.