Description
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This issue is fixed in version 8.5.0.
Published: 2026-07-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Snipe‑IT versions prior to 8.5. private upload‑directory path, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This vulnerability, classified as CWE‑23, can lead to the disclosure of sensitive system or application data without affecting integrity or availability.

Affected Systems

The affected product is the Snipe‑IT IT asset management system from grokability. All releases before version 8.5.0 are impacted; later versions include the fix.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity risk. that the The EPSS score of < 1% demonstrates that exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog, so there are no known active exploitation campaigns targeting it. Nevertheless, environments with exposed or minimally protected Snipe‑IT instances remain at risk.

Generated by OpenCVE AI on July 28, 2026 at 08:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.5.0 or newer, which contains the patch be applied immediately, restrict or disable the ActionlogController::displaySig endpoint for all non‑admin roles, preventing authenticated users from invoking the vulnerable functionality.
  • As a short‑term containment measure, configure the web server to limit file read permissions to the intended upload directories and disable directory listing to reduce the damage surface.
  • Add network segmentation or firewall rules to isolate the Snipe‑IT instance from critical server components, limiting potential lateral movement if an attacker gains access to arbitrary files.

Generated by OpenCVE AI on July 28, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Fri, 10 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This issue is fixed in version 8.5.0.
Title Snipe-IT: Directory traversal in displaySig
Weaknesses CWE-23
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-10T19:12:30.256Z

Reserved: 2026-06-16T22:10:37.609Z

Link: CVE-2026-55474

cve-icon Vulnrichment

Updated: 2026-07-10T19:12:25.725Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:15:06Z

Weaknesses
  • CWE-23

    Relative Path Traversal