THREAT OPS › Threat News › [GHSA] GHSA-j5g3-42wp-gqm3 (high) — Snipe-IT has an Improper Privilege Management issue
[GHSA] GHSA-j5g3-42wp-gqm3 (high) — Snipe-IT has an Improper Privilege Management issue
GHSA-j5g3-42wp-gqm3 Severity: high CVE: CVE-2026-55843
Snipe-IT has an Improper Privilege Management issue
## Impact
The `update()` method in `UsersController` passes the `permission` request field unconditionally to `NormalizePermissionsPayloadAction`, which returns an empty array when the field is absent. The result is passed to `PreserveUnauthorizedPrivilegedPermissionsAction`, which selecti
Indicators of compromise
- 1cff2d67aabd00ee51d864c1d7fb717494c1d6adsha1
- CVE-2026-55843cve
Original source: https://github.com/advisories/GHSA-j5g3-42wp-gqm3