THREAT OPS › Threat News › [GHSA] GHSA-crv3-j83j-f3r6 (medium) — Snipe-IT has missing object-level authorization in Kits API
[GHSA] GHSA-crv3-j83j-f3r6 (medium) — Snipe-IT has missing object-level authorization in Kits API
GHSA-crv3-j83j-f3r6 Severity: medium CVE: CVE-2026-55478
Snipe-IT has missing object-level authorization in Kits API
### Impact The API endpoint for adding a license to a predefined kit (`POST /api/v1/kits/{kit_id}/licenses`) only checks whether the caller can edit kits, but does not perform object-level authorization on the referenced license itself. Because of this, a low-privilege user with o
Indicators of compromise
- CVE-2026-55478cve
Original source: https://github.com/advisories/GHSA-crv3-j83j-f3r6