CVE-2026-55475: Snipe-IT: Import created_by can be overwritten
Impact The createdby of an import file can be arbitrarily overwritten via the Importer API endpoint by a user with CSV import capabilities who also has a valid API key.
Other sources
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the createdby value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 8.6.1 - Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55475?
CVE-2026-55475 has a medium severity rating of 5.7.
How does CVE-2026-55475 affect the Snipe-IT system?
CVE-2026-55475 allows a user to overwrite the created_by value of an import file, enabling unauthorized modification of ownership metadata.
What versions of Snipe-IT are affected by CVE-2026-55475?
CVE-2026-55475 affects Snipe-IT versions prior to 8.6.1.
How do I fix CVE-2026-55475?
To fix CVE-2026-55475, upgrade Snipe-IT to version 8.6.1 or later.
Who is at risk with CVE-2026-55475?
Users with CSV import capabilities and a valid API key are at risk with CVE-2026-55475.