THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8frh-vhgh-64cf (medium) — Snipe-IT has incorrect permission for legacy license checkin API

[GHSA] GHSA-8frh-vhgh-64cf (medium) — Snipe-IT has incorrect permission for legacy license checkin API

medgithub_advisoriesPublished 2026-08-28

GHSA-8frh-vhgh-64cf Severity: medium CVE: CVE-2026-55479

Snipe-IT has incorrect permission for legacy license checkin API

### Impact The legacy single-seat license checkin flow authorizes the action with the `checkout` permission instead of the `checkin` permission. Because of this, a user who is allowed to assign licenses but not unassign them can still directly access the old checkin endpoint

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8frh-vhgh-64cf