Tag
high
advisory
Broken Access Control in Snipe-IT Asset Maintenance API
2 rules 2 TTPs 1 CVEAn authenticated user in a multi-company Snipe-IT deployment can exploit an authorization flaw in the asset maintenance update API to re-parent records to assets owned by other companies, breaking tenant isolation.
Snipe-IT +2
web-application
privilege-escalation
multi-tenant
web-application-vulnerability
path-traversal
cve-2026-55474
authorization-bypass
asset-management
2r
2t
1c
high
advisory
OpenRemote Cross-Realm User Information Disclosure (CVE-2026-54641)
1 rule 2 TTPsA high-severity vulnerability (CVE-2026-54641) in OpenRemote's `UserResourceImpl.java` allows a realm administrator in a multi-tenant deployment to perform cross-realm user enumeration and privilege-level reconnaissance by reading sensitive user information (profile, client roles, and realm roles) from any other realm, including the master realm, due to missing authorization checks in specific REST API endpoints.
openremote-manager
OpenRemote
Vulnerability
API
Information Disclosure
Access Control
Multi-tenant
1r
2t