Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.
References
Configurations
History
10 Jul 2026, 20:13
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Snipeitapp
Snipeitapp snipe-it |
|
| CPE | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| References | () https://github.com/grokability/snipe-it/commit/6a0ec6945126a79fc25c0990c99abe632db370c3 - Patch | |
| References | () https://github.com/grokability/snipe-it/commit/dc8cbf4786bb38b260b4ae1723ec9e7f81d82fe5 - Patch | |
| References | () https://github.com/grokability/snipe-it/commit/e2bea57146eb3a3781b5eb21b69d7e04cc87c268 - Patch | |
| References | () https://github.com/grokability/snipe-it/releases/tag/v8.6.2 - Release Notes | |
| References | () https://github.com/grokability/snipe-it/security/advisories/GHSA-pwpj-p52h-q484 - Patch, Vendor Advisory |
10 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 19:17
Updated : 2026-07-10 21:16
NVD link : CVE-2026-54329
Mitre link : CVE-2026-54329
CVE.ORG link : CVE-2026-54329
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-862
Missing Authorization
