SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-55452

HIGH · CVSS 7.3 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Snipe-IT versions prior to 8.5.0 are vulnerable due to improper handling of the User-Agent header in the Activity Report CSV, allowing low-privileged authenticated users to inject formula-like content. This could lead to arbitrary code execution when the CSV is opened in spreadsheet applications, posing a significant risk to users who access these reports. Organizations using Snipe-IT should prioritize upgrading to version 8.5.0 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55452
Severity
HIGH
CVSS
7.3
EPSS
0.23%

Original NVD Description

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like User-Agent that may execute when a report viewer opens the exported CSV in spreadsheet software. This issue is fixed in version 8.5.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)