PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50550 grokability CVE debrief

CVE-2026-50550 debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:18.380Z and has not been modified since then. Snipe-IT versions prior to 8.5.0 are vulnerable to a security issue where users with edit permissions can reset a superadmin's two-factor authentication. This issue is fixed in version 8.5.0. Defenders managing Snipe-IT deployments should assess exposure, especially those with user roles that allow editing other users' information, and prioritize remediation to prevent potential security incidents. Verification of Snipe-IT version and user role configurations is necessary to prevent unauthorized two-factor authentication resets.

Vendor
grokability
Product
snipe-it
CVSS
MEDIUM 5.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-09-09
Advisory published
2026-08-19
Advisory updated
2026-09-09

Who should care

Defenders managing Snipe-IT deployments, especially those with user roles that allow editing other users' information, should assess exposure and verify if their instances are vulnerable.

Why it matters

CVE-2026-50550 is a vulnerability in Snipe-IT that allows users with edit permissions to reset a superadmin's two-factor authentication. Defenders should verify exposure, especially in deployments with permissive user roles, and prioritize remediation to prevent potential security incidents.

  • Verification of Snipe-IT version and user role configurations is necessary to prevent unauthorized two-factor authentication resets.
  • Defenders should assess the impact of potential resets of superadmin's two-factor authentication on their operational security.
  • Remediation priority should be given to Snipe-IT instances with user roles that allow editing other users' information.

Technical summary

In Snipe-IT versions prior to 8.5.0, a user with edit permissions for other users can reset a superadmin's two-factor authentication through the postTwoFactorReset endpoint in app/Http/Controllers/Api/UsersController.php. This issue is fixed in version 8.5.0. The vulnerability allows users with edit permissions to reset a superadmin's two-factor authentication, potentially leading to security incidents. Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user roles allow editing other users' information, and assess the impact of resetting superadmin's two-factor authentication.

Defensive priority

Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user roles allow editing other users' information, and assess the impact of resetting superadmin's two-factor authentication.

Recommended defensive actions

  • Verify Snipe-IT version and ensure it is 8.5.0 or later
  • Review user roles and restrict edit permissions for sensitive operations
  • Monitor for suspicious activity related to two-factor authentication resets
  • Perform a thorough review of Snipe-IT configurations and user roles to prevent unauthorized access
  • Implement additional monitoring for two-factor authentication reset events
  • Verify that all superadmin accounts have secure two-factor authentication configurations
  • Conduct regular security audits to identify and address potential vulnerabilities

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Snipe-IT versions prior to 8.5.0, where a user who can edit other users can reset a superadmin's two-factor authentication. The issue is fixed in version 8.5.0. Evidence is limited to public CVE and NVD information. Defenders should verify Snipe-IT version and review user roles to assess exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-50550 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-50550

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-50550 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50550

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.