What is CVE-2026-55483?
CVE-2026-55483 is a privilege escalation vulnerability in the Snipe-IT asset management system. Before version 8.6.0, an authenticated user with 'users.create' permission could grant themselves or another user admin privileges during user creation due to a lack of sanitization of the 'admin' permission in the UserController. Immediate upgrade to version 8.6.0 or later is required.
Azərbaycanca: CVE-2026-55483: Snipe-IT aktiv idarəetmə sistemində aşkar edilmiş imtiyaz yüksəltmə zəifliyidir. 8.6.0 versiyasından əvvəl, `users.create` icazəsi olan autentifikasiya olunmuş istifadəçi yeni istifadəçi yaradarkən `admin` icazəsini də verə bilər. Təcili olaraq Snipe-IT versiyasını ən az 8.6.0-a yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which software product is affected by CVE-2026-55483?
This vulnerability affects the Snipe-IT asset management system.
What initial permission must an attacker have to exploit CVE-2026-55483?
The attacker must be an authenticated user with 'users.create' permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.