Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
Published: 2026-07-10
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Importer API endpoint in Snipe-IT allows a user with CSV import permissions and a valid API key to overwrite the created_by value of an import file. This flaw permits an attacker to alter ownership metadata of imports, which can undermine audit trails and the integrity of asset tracking data.

Affected Systems

Grokability Snipe‑IT products are affected. Any release prior to version 8.6.1 is vulnerable; the issue was fixed in release 8.6.1.

Risk and Exploitability

The CVSS score of 5.7 categorizes the vulnerability as moderate. The EPSS score of < 1 % indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. The attack vector requires a valid API key and import privileges, so the threat primarily targets users with legitimate access or those who compromise an authorized credential. The impact is confined to metadata integrity rather than direct data or system compromise.

Generated by OpenCVE AI on July 26, 2026 at 13:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.6.1 and enforce role‑based access control
  • Audit import records periodically to detect unauthorized changes to ownership metadata
  • Restrict CSV import permissions to minimum necessary roles

Generated by OpenCVE AI on July 26, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
Title Snipe-IT: Import created_by can be overwritten
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-13T16:11:50.638Z

Reserved: 2026-06-16T22:10:37.609Z

Link: CVE-2026-55475

cve-icon Vulnrichment

Updated: 2026-07-13T16:11:47.296Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T13:15:17Z

Weaknesses