SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-55462

MEDIUM · CVSS 4.3 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Snipe-IT IT asset/license management system, where prior to version 8.6.2, the UsersController::show() and printInventory() functions inadequately authorize user permissions, allowing authenticated users with limited access to view sensitive inventory and cost/order metadata. This could lead to unauthorized visibility of information that should be restricted based on user roles. Organizations using versions prior to 8.6.2 should prioritize upgrading to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55462
Severity
MEDIUM
CVSS
4.3
EPSS
0.28%

Original NVD Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)