Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/grokability/snipe-it/security/advisories/GHSA-5wx7-xq8j-v4qm
X_Refsource_Misc x_refsource_misc
https://github.com/grokability/snipe-it/pull/19072
X_Refsource_Misc x_refsource_misc
https://github.com/grokability/snipe-it/commit/39fbe983132feca2ef15c1c0200fcc77c23a1434
X_Refsource_Misc x_refsource_misc
https://github.com/grokability/snipe-it/releases/tag/v8.6.1
Scores
CVSS v3
5.7
EPSS
0.0019
EPSS Percentile
9.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
grokability/snipe-it
< 8.6.1
snipeitapp/snipe-it
< 8.6.1
Published
Jul 10, 2026
Tracked Since
Jul 11, 2026