AUGUST 31, 2026
Live Feed
Back to database
Case File

CVE-2026-55475

MEDIUM · CVSS 5.7 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The Importer API endpoint in Snipe-IT prior to version 8.6.1 is vulnerable, allowing users with CSV import capabilities and a valid API key to unauthorizedly modify the ownership metadata of import files. This could lead to incorrect attribution of asset ownership, potentially compromising asset management integrity. Organizations using Snipe-IT should prioritize upgrading to version 8.6.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55475
Severity
MEDIUM
CVSS
5.7
EPSS
0.19%

Original NVD Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)