What is CVE-2026-55482?
CVE-2026-55482 is a multi-tenancy bypass vulnerability in the Snipe-IT asset management system. Prior to version 8.4.1, a non-superadmin user could manipulate the bulk asset update function by directly submitting the company_id parameter, allowing assets to be moved across company boundaries. Upgrading to version 8.4.1 is strongly recommended to maintain multi-tenancy isolation.
Azərbaycanca: CVE-2026-55482, Snipe-IT aktiv idarəetmə sistemində müəyyən edilmiş multi-tenancy məhdudiyyətindən yan keçmə zəifliyidir. 8.4.1 versiyasından əvvəl, super admin olmayan istifadəçi bulk asset yeniləmə funksiyası vasitəsilə company_id parametrini bilavasitə göndərərək aktivləri şirkətlər arası köçürə bilir. Sistemin multi-tenancy arxitekturasını qorumaq üçün dərhal 8.4.1 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What action can be performed by exploiting CVE-2026-55482?
Through this vulnerability, a non-superadmin user can transfer assets from one company to another by directly submitting the `company_id` parameter to the bulk asset update function.
To which version should one upgrade to fix CVE-2026-55482?
To address this vulnerability, it is recommended to upgrade the Snipe-IT system to version 8.4.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.