PatchSiren cyber security CVE debrief
CVE-2026-50550 grokability CVE debrief
CVE-2026-50550 debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:18.380Z and has not been modified since then. Snipe-IT versions prior to 8.5.0 are vulnerable to a security issue where users with edit permissions can reset a superadmin's two-factor authentication. This issue is fixed in version 8.5.0. Defenders managing Snipe-IT deployments should assess exposure, especially those with user roles that allow editing other users' information, and prioritize remediation to prevent potential security incidents. Verification of Snipe-IT version and user role configurations is necessary to prevent unauthorized two-factor authentication resets.
- Vendor
- grokability
- Product
- snipe-it
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-09
Who should care
Defenders managing Snipe-IT deployments, especially those with user roles that allow editing other users' information, should assess exposure and verify if their instances are vulnerable.
Why it matters
CVE-2026-50550 is a vulnerability in Snipe-IT that allows users with edit permissions to reset a superadmin's two-factor authentication. Defenders should verify exposure, especially in deployments with permissive user roles, and prioritize remediation to prevent potential security incidents.
- Verification of Snipe-IT version and user role configurations is necessary to prevent unauthorized two-factor authentication resets.
- Defenders should assess the impact of potential resets of superadmin's two-factor authentication on their operational security.
- Remediation priority should be given to Snipe-IT instances with user roles that allow editing other users' information.
Technical summary
In Snipe-IT versions prior to 8.5.0, a user with edit permissions for other users can reset a superadmin's two-factor authentication through the postTwoFactorReset endpoint in app/Http/Controllers/Api/UsersController.php. This issue is fixed in version 8.5.0. The vulnerability allows users with edit permissions to reset a superadmin's two-factor authentication, potentially leading to security incidents. Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user roles allow editing other users' information, and assess the impact of resetting superadmin's two-factor authentication.
Defensive priority
Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user roles allow editing other users' information, and assess the impact of resetting superadmin's two-factor authentication.
Recommended defensive actions
- Verify Snipe-IT version and ensure it is 8.5.0 or later
- Review user roles and restrict edit permissions for sensitive operations
- Monitor for suspicious activity related to two-factor authentication resets
- Perform a thorough review of Snipe-IT configurations and user roles to prevent unauthorized access
- Implement additional monitoring for two-factor authentication reset events
- Verify that all superadmin accounts have secure two-factor authentication configurations
- Conduct regular security audits to identify and address potential vulnerabilities
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Snipe-IT versions prior to 8.5.0, where a user who can edit other users can reset a superadmin's two-factor authentication. The issue is fixed in version 8.5.0. Evidence is limited to public CVE and NVD information. Defenders should verify Snipe-IT version and review user roles to assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-50550 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-50550
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-50550 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50550
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/commit/046ef82c6501be14df597f0bf5d0de2566c7d6bc
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/releases/tag/v8.5.0
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-6x4j-8954-5hxm
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.