THREAT OPS › Threat News › [GHSA] GHSA-575r-357h-fhch (high) — Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
[GHSA] GHSA-575r-357h-fhch (high) — Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
GHSA-575r-357h-fhch Severity: high CVE: CVE-2026-55516
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
### Impact The API endpoint for updating asset maintenance records allows an authorized user to change the asset_id of an existing maintenance record to an asset outside their company scope.
In a Full Multiple Company Support / multi-company deployment, this
Indicators of compromise
- CVE-2026-55516cve
Original source: https://github.com/advisories/GHSA-575r-357h-fhch