THREAT OPS › Threat News › [GHSA] GHSA-8frh-vhgh-64cf (medium) — Snipe-IT has incorrect permission for legacy license checkin API
[GHSA] GHSA-8frh-vhgh-64cf (medium) — Snipe-IT has incorrect permission for legacy license checkin API
GHSA-8frh-vhgh-64cf Severity: medium CVE: CVE-2026-55479
Snipe-IT has incorrect permission for legacy license checkin API
### Impact The legacy single-seat license checkin flow authorizes the action with the `checkout` permission instead of the `checkin` permission. Because of this, a user who is allowed to assign licenses but not unassign them can still directly access the old checkin endpoint
Indicators of compromise
- CVE-2026-55479cve
Original source: https://github.com/advisories/GHSA-8frh-vhgh-64cf