THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-575r-357h-fhch (high) — Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

[GHSA] GHSA-575r-357h-fhch (high) — Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

medgithub_advisoriesPublished 2026-08-28

GHSA-575r-357h-fhch Severity: high CVE: CVE-2026-55516

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

### Impact The API endpoint for updating asset maintenance records allows an authorized user to change the asset_id of an existing maintenance record to an asset outside their company scope.

In a Full Multiple Company Support / multi-company deployment, this

Indicators of compromise

Original source: https://github.com/advisories/GHSA-575r-357h-fhch