Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.
Published: 2026-07-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Snipe-IT, an IT asset and license management application, contains a path‑traversal flaw in its CSV import routine. An attacker who can authenticate to the system and holds the import and assets.update permissions can embed a traversal sequence in the image field of a CSV record. When the system subsequently deletes the referenced image, the path is resolved against the underlying file system, permitting removal of any file reachable by the server process. This results in loss of data and can disrupt services that rely on the deleted assets. The weakness is classified as CWE‑22 and carries a CVSS score of 6.5.

Affected Systems

The flaw exists in all Snipe-IT releases earlier than version 8.6.2. Versions 8.6.2 and later include the fix and are not affected.

Risk and Exploitability

The CVSS score denotes moderate severity. An EPSS value of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The attacker must already have authenticated access with import and assets.update rights, so the threat primarily comes from insiders or compromised legitimate users. Once those privileges are in place, the attacker can delete any file that the server user can access.

Generated by OpenCVE AI on July 29, 2026 at 10:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe-IT to version 8.6.2 or later, where the path-traversal bug is fixed.
  • Restrict the import and assets.update permissions to a minimal set of trusted administrators.
  • If an upgrade cannot be performed immediately tighten directory allowances so that only the intended image folder can be targeted.

Generated by OpenCVE AI on July 29, 2026 at 10:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.
Title Snipe-IT: Path traversal vulnerability via CSV import `image` field
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-10T20:16:14.160Z

Reserved: 2026-06-16T22:10:37.608Z

Link: CVE-2026-55469

cve-icon Vulnrichment

Updated: 2026-07-10T20:16:11.179Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')