CVE-2026-55469: Snipe-IT: Path traversal vulnerability via CSV import `image` field
Impact An authenticated user holding the import and assets.update permissions can delete arbitrary files on the server filesystem by injecting a path traversal string into an asset's image field via CSV import, then triggering the image deletion feature.
Other sources
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 8.6.2 - Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55469?
The severity of CVE-2026-55469 is medium with a score of 6.5.
How do I fix CVE-2026-55469?
To fix CVE-2026-55469, upgrade to Snipe-IT version 8.6.2 or later.
What is the risk associated with CVE-2026-55469?
The risk associated with CVE-2026-55469 is rated as 49, indicating a potential for significant impact.
What kind of vulnerability is CVE-2026-55469?
CVE-2026-55469 is a path traversal vulnerability that allows unauthorized file deletion.
Who is affected by CVE-2026-55469?
Authenticated users with import and assets.update permissions in Snipe-IT prior to version 8.6.2 are affected by CVE-2026-55469.