CVE-2026-55469: Snipe-IT: Path traversal vulnerability via CSV import `image` field
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55469?
The severity of CVE-2026-55469 is medium with a score of 6.5.
How do I fix CVE-2026-55469?
To fix CVE-2026-55469, upgrade to Snipe-IT version 8.6.2 or later.
What is the risk associated with CVE-2026-55469?
The risk associated with CVE-2026-55469 is rated as 49, indicating a potential for significant impact.
What kind of vulnerability is CVE-2026-55469?
CVE-2026-55469 is a path traversal vulnerability that allows unauthorized file deletion.
Who is affected by CVE-2026-55469?
Authenticated users with import and assets.update permissions in Snipe-IT prior to version 8.6.2 are affected by CVE-2026-55469.