Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-54329

35
FAUCET Score

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2.

First published: Jul 10, 2026Last modified: Jul 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 8.6.2CPE matchmatch criteria
cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.5HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.1
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
13.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 3rd percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: snipe/snipe-itFixed in: 8.6.2
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-pwpj-p52h-q484high

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Jun 23, 2026

References

github.com / grokability/snipe-it/commit/6a0ec6945126a79fc25c0990c99abe632db370c3
Patch
github.com / grokability/snipe-it/commit/dc8cbf4786bb38b260b4ae1723ec9e7f81d82fe5
Patch
github.com / grokability/snipe-it/commit/e2bea57146eb3a3781b5eb21b69d7e04cc87c268
Patch
github.com / grokability/snipe-it/releases/tag/v8.6.2
Release Notes
github.com / grokability/snipe-it/security/advisories/GHSA-pwpj-p52h-q484
PatchVendor Advisory