PT-2026-57288 · Snipe-It · Snipe-It

CVE-2026-55475

·

Published

2026-07-10

·

Updated

2026-08-28

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.6.1
Description The Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created by value of an import file. This leads to the unauthorized modification of import ownership metadata.
Recommendations Update to version 8.6.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55475
GHSA-5WX7-XQ8J-V4QM

Affected Products

Snipe-It