SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-55542

MEDIUM · CVSS 4.3 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

Snipe-IT versions prior to 8.6.1 are vulnerable due to inadequate authorization in the S3 signature image retrieval process, allowing authenticated users to generate a temporary signed URL for any signature filename. This could lead to unauthorized access to sensitive images stored in S3, potentially exposing confidential data. Organizations using Snipe-IT should prioritize upgrading to version 8.6.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55542
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%

Original NVD Description

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file branch. Version 8.6.1 contains a patch.

Related CVEs

Other vulnerabilities affecting the same vendor(s)