THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8w8c-8mx9-52cw (medium) — Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

[GHSA] GHSA-8w8c-8mx9-52cw (medium) — Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

highgithub_advisoriesPublished 2026-08-28

GHSA-8w8c-8mx9-52cw Severity: medium CVE: CVE-2026-55472

Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation

### Impact When Full Multiple Companies Support and scope_locations_fmcs are both enabled, the API endpoint for creating locations can still create a child location under a parent location from a different company. The code detects the invalid parent/ch

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8w8c-8mx9-52cw