← Back

CVE-2026-55475

nvd nist
Published: Jul 10, 2026Modified: Jul 14, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.1 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.

Affected (1)

Products: Snipeitapp: Snipe It
1 product
Snipe It
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.6.1

References (4)

Source: security-advisories@github.com
PatchIssue Tracking
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
PatchVendor Advisory

Timeline

No history available yet.