THREAT OPS › Threat News › [GHSA] GHSA-8w8c-8mx9-52cw (medium) — Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
[GHSA] GHSA-8w8c-8mx9-52cw (medium) — Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
GHSA-8w8c-8mx9-52cw Severity: medium CVE: CVE-2026-55472
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
### Impact When Full Multiple Companies Support and scope_locations_fmcs are both enabled, the API endpoint for creating locations can still create a child location under a parent location from a different company. The code detects the invalid parent/ch
Indicators of compromise
- 9a8cbd6e00613a726b639a97a1da71b3c54f9489sha1
- CVE-2026-55472cve
Original source: https://github.com/advisories/GHSA-8w8c-8mx9-52cw