PT-2026-51646 · Git+3 · Snipe-It+1
CVE-2026-55542
·
Published
2026-06-23
·
Updated
2026-07-13
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.6.1
Description
In S3-backed deployments, the system fails to perform authorization checks before generating temporary URLs for signature image retrieval. Authenticated users who possess a signature filename can obtain a signed S3 URL valid for 5 minutes because the S3 logic branch returns a response before the
authorize() function is executed.Recommendations
Update to version 8.6.1.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It
Snipe/Snipe-It