highCVSS 6.5Vulnerability

CVE-2026-55843

## Impact The `update()` method in `UsersController` passes the `permission` request field unconditionally to `NormalizePermissionsPayloadAction`, which returns an empty array when the field is absent. The result is passed to `PreserveUnauthorizedPrivilegedPermissionsAction`, which selectively restores only the `superuser` key (when the editor is not a superuser) and the `admin` key (when the editor is neither admin nor superuser). All other permissions — including the `admin` flag itself when the editing user is an admin — are discarded and `$user->permissions` is overwritten with the sparse result. The `canEditAuthFields` gate permits admins to update other non-superuser accounts (including other admins). When an admin sends a `PUT /users/{id}` request for another admin without including the `permission` field, the target's `admin` flag and all granular permissions are permanently destroyed. The target loses administrative access entirely with no error, warning, or out-of-band notification. A secondary, lower-impact path exists for non-admin users holding the `users.edit` permission: they may target regular (non-admin, non-superuser) accounts and wipe all granular permissions in the same way. ### Patches Patched in https://github.com/grokability/snipe-it/commit/1cff2d67aabd00ee51d864c1d7fb717494c1d6ad

Properties

ghsa_id
GHSA-j5g3-42wp-gqm3
severity
high
summary
Snipe-IT has an Improper Privilege Management issue
cvss_score
6.5
cve_id
CVE-2026-55843
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-08-28T22:37:24Z
source_url
https://github.com/advisories/GHSA-j5g3-42wp-gqm3
ghsa_updated
2026-08-28T22:37:25Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]composer/snipe/snipe-it

AFFECTS (1)

[Software]composer/snipe/snipe-it

HAS_WEAKNESS (1)

[Weakness]Improper Privilege Management

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55843 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal