CVE-2026-55542
MEDIUMSnipe-IT's S3 signature image retrieval lacks authorization before temporary URL
Title source: cnaDescription
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file branch. Version 8.6.1 contains a patch.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/grokability/snipe-it/security/advisories/GHSA-6mmj-jhqj-6c6q
X_Refsource_Misc x_refsource_misc
https://github.com/grokability/snipe-it/commit/ded6515cbc27a28f07395da318483c2e96263259
Scores
CVSS v3
4.3
EPSS
0.0017
EPSS Percentile
6.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
grokability/snipe-it
< 8.5.1
snipeitapp/snipe-it
< 8.6.0
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026