These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-55460 is a high-severity vulnerability in Snipe-IT, an IT asset/license management system. An authenticated non-admin user with users.view and users.edit but without users.delete permissions can soft-delete another non-admin user by directly posting to /users/bulksave with delete_user=1. This is possible because the BulkUsersController::destroy() method only authorizes updates, not deletions. The [truncated]
CVE-2026-54329 is a high-severity vulnerability in Snipe-IT's Accessories API. Prior to version 8.6.2, the API's create path mass-assigns request parameters to the Accessory model, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2. The vulnerability exists due t [truncated]
CVE-2026-48492 is a medium-severity vulnerability in Snipe-IT's API endpoint, which lacks an authorization check. This allows any logged-in user to retrieve a paginated list of all user accounts, exposing sensitive information such as usernames, display names, employee numbers, and user IDs. The exposure affects active accounts, and its impact varies depending on whether FMCS is enabled. To mitigate this [truncated]
CVE-2026-55542 involves Snipe-IT, an IT asset/license management system. Prior to version 8.6.1, Snipe-IT's S3 signature image retrieval process lacks proper authorization before generating a temporary URL. This issue affects S3-backed deployments. Authenticated users who are aware of a signature filename can obtain a 5-minute signed S3 URL. This occurs because the S3 branch returns before the authorize() [truncated]
CVE-2026-48493 is a medium-severity vulnerability in Snipe-IT versions prior to 8.6.0. The issue allows a user with only 'users.edit' permission to send a PATCH request to /api/v1/users/{their_own_id} and grant themselves any permission except 'admin' and 'superuser'. This could potentially lead to unauthorized access or actions within the system. The vulnerability is patched in version 8.6.0. Users of Sn [truncated]
An open redirect vulnerability in Snipe-IT IT asset/license management system allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. The vulnerability exists in versions prior to 8.4.1 and was fixed in version 8.4.1. The CVSS 3.1 vector indicates attack vector is adjacent network, low attack complexity, low privileges required, user interactio [truncated]
An authenticated privilege escalation vulnerability in Snipe-IT allows users with only users.edit permission to grant themselves full administrative access. The API endpoint /api/v1/users/{id} fails to properly validate permission modifications, stripping only the superuser key while permitting admin and other elevated permissions to be set. This represents an authorization bypass where insufficient serve [truncated]
A stored cross-site scripting (XSS) vulnerability exists in Snipe-IT, an open-source IT asset and license management platform. The flaw affects versions prior to 8.4.1 and resides in the unescaped rendering of the notes column within the components module. Users with component view access can trigger or be affected by this vulnerability when malicious scripts are embedded in notes fields and subsequently [truncated]