CVE-2026-55475
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.1 / Impact: 3.6
Source: security-advisories@github.com (Secondary)
Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
Affected (1)
Products: Snipeitapp: Snipe It
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.6.1 |
References (4)
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
PatchIssue Tracking
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
PatchVendor Advisory
Timeline
No history available yet.