CVE-2026-55476Disclosure(snipeitapp / snipe-it)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim user ID and silently cancel that user’s pending asset requests. This issue is fixed in version 8.6.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • snipe-it

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-10); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
snipe-it

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-05: 1Mentions · 2026-07-10: 2Mentions · 2026-07-13: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-13: 107-0507-1007-13
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-051
Disclosure1
2026-07-102
Disclosure1General1
2026-07-131
General1
Full discourse4 posts
  • BBWriteup@bbwriteup
    Disclosure

    "CVE-2026–55476: Snipe-IT Unauthorized Asset Request Cancellation via cancel_by_admin IDOR" by Ali İltizar #InfoSec #CyberSecurity #Hacking #BugBounty https://medium.com/@alii76tt/cve-2026-55476-snipe-it-unauthorized-asset-request-cancellation-via-cancel-by-admin-idor-7c439b2ae13e

    Post summary

    The Medium article announces a new IDOR vulnerability (CVE‑2026‑55476) in Snipe‑IT that allows unauthorized asset request cancellation via the cancel_by_admin endpoint, but no PoC, exploit code, active exploitation, or patch is discussed.

    00010153
    760 followersView on X
  • DailyCVE@dailycve
    General

    🟠 Snipe-IT, Missing Authorization, #CVE-2026-55476 (Medium) -DC-Jul2026-877 https://dailycve.com/snipe-it-missing-authorization-cve-2026-55476-medium-dc-jul2026-877/

    Post summary

    The post references CVE-2026-55476 for Snipe‑IT, noting a missing authorization flaw rated Medium, but it provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000046
    218 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-55476 Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_ad… https://www.cve.org/CVERecord?id=CVE-2026-55476 ----- Traducción: CVE-2026-55476 Sni… http://infoflow.cloud`

    Post summary

    The text introduces CVE-2026-55476, noting a flaw in Snipe-IT’s account request endpoint that permits unauthorized cancellation before version 8.6.0, but provides no evidence of active exploitation, patch, or PoC.

    0000037
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55476 Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_ad… https://www.cve.org/CVERecord?id=CVE-2026-55476

    Post summary

    The post references CVE-2026-55476 and describes an endpoint in Snipe‑IT before v8.6.0 that accepts a cancel_by_admin parameter, but it does not provide a PoC, exploit, active use evidence, or a patch.

    00000680
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsnipeitappsnipe-it---

Explore more