What is CVE-2026-55643?
A vulnerability was found in Snipe-IT IT asset management system prior to version 8.6.3, where a company-scoped user in FMCS floater mode could access users with a null company_id due to inconsistent application of `isCurrentUserHasAccess` checks on broad API queries. Users should upgrade to version 8.6.3 or later immediately.
Azərbaycanca: Snipe-IT aktiv idarəetmə sistemində CVE-2026-55643 zəifliyi aşkar edilib. 8.6.3 versiyasından əvvəl, FMCS floater rejimində olan şirkət əhatəli istifadəçi, `isCurrentUserHasAccess` yoxlamasının API sorğularında tam tətbiq edilməməsi səbəbindən `company_id` dəyəri null olan istifadəçilərə giriş əldə edə bilər. Snipe-IT istifadəçiləri dərhal 8.6.3 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which users are affected by CVE-2026-55643 in Snipe-IT?
Company-scoped users in FMCS floater mode can gain unauthorized access to users with a null company_id.
How can I fix the CVE-2026-55643 vulnerability?
You should immediately upgrade Snipe-IT to version 8.6.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.