PT-2026-57287 · Snipe-It · Snipe-It

CVE-2026-55469

·

Published

2026-07-10

·

Updated

2026-08-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.6.2
Description An authenticated user with import and assets.update permissions can perform a path traversal attack by inserting a malicious string into an asset image field during a CSV import. By subsequently triggering the image deletion process, the user can delete arbitrary files that are accessible to the server process. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update to version 8.6.2.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55469
GHSA-XR9M-GPHC-9P63

Affected Products

Snipe-It