THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j5g3-42wp-gqm3 (high) — Snipe-IT has an Improper Privilege Management issue

[GHSA] GHSA-j5g3-42wp-gqm3 (high) — Snipe-IT has an Improper Privilege Management issue

highgithub_advisoriesPublished 2026-08-28

GHSA-j5g3-42wp-gqm3 Severity: high CVE: CVE-2026-55843

Snipe-IT has an Improper Privilege Management issue

## Impact

The `update()` method in `UsersController` passes the `permission` request field unconditionally to `NormalizePermissionsPayloadAction`, which returns an empty array when the field is absent. The result is passed to `PreserveUnauthorizedPrivilegedPermissionsAction`, which selecti

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j5g3-42wp-gqm3