CVE-2026-55475: Snipe-IT: Import created_by can be overwritten
Published Jul 10, 2026
·Updated
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the createdby value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
Affected Software
2 affected components
Snipe-IT Snipe-IT<8.6.1
Snipeitapp Snipe-it<8.6.1
Remediation
Patch Available
Event History
Jul 10, 2026
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-55475?
CVE-2026-55475 has a medium severity rating of 5.7.
2
How does CVE-2026-55475 affect the Snipe-IT system?
CVE-2026-55475 allows a user to overwrite the created_by value of an import file, enabling unauthorized modification of ownership metadata.
3
What versions of Snipe-IT are affected by CVE-2026-55475?
CVE-2026-55475 affects Snipe-IT versions prior to 8.6.1.
4
How do I fix CVE-2026-55475?
To fix CVE-2026-55475, upgrade Snipe-IT to version 8.6.1 or later.
5
Who is at risk with CVE-2026-55475?
Users with CSV import capabilities and a valid API key are at risk with CVE-2026-55475.