ZeroHour

CVE-2026-54329

CVSS 3.1
7.7 high
EPSS
<1%p32
Published
()
Modified
Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.

Vendors
snipeitapp
Products
snipe-it
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.