What is CVE-2026-50550?
This vulnerability exists in Snipe-IT asset management system before version 8.5.0, where a user with permissions to edit other users can reset a superadmin's two-factor authentication via the `postTwoFactorReset()` method in `UsersController.php`. The endpoint fails to enforce `canEditAuthField` restrictions. Upgrading to the latest version is strongly recommended to mitigate the risk.
Azərbaycanca: Bu boşluq Snipe-IT aktiv idarəetmə sistemində aşkarlanıb. 8.5.0 versiyasından əvvəl, digər istifadəçiləri redaktə edə bilən istifadəçi `UsersController.php` faylındakı `postTwoFactorReset()` funksiyası vasitəsilə superadminin iki faktorlu autentifikasiyasını sıfırlaya bilər. Zəiflikdən qorunmaq üçün sistemi dərhal ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which software is affected by CVE-2026-50550 and in what versions?
This vulnerability exists in Snipe-IT asset management system in versions before 8.5.0.
How can the CVE-2026-50550 vulnerability be mitigated?
Upgrading Snipe-IT to the latest version is strongly recommended to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.