medium

CVE-2026-55483

Packagist · snipe/snipe-it

Summary

Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation

Severity
medium
EPSS
0.3% (p23)
CWE
CWE-862
Also known as
GHSA-hf68-g98v-wp9g
Published
2026-06-23
Updated
2026-06-23

Advisory details

Impact

The store() method in both the web and API UsersController only strips the superuser permission when a non-superuser creates a user. It does not strip the admin permission. This allows any authenticated user with the users.create permission to create a new user with full admin privileges.

The users.create permission may commonly be delegated to HR staff, department leads, or similar roles.

Patches

Patched in aea3877718

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.