Improper access control in snipe-it - CVE-2026-55475
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite the created_by field of an import file.
The vulnerability exists due to improper access control in the Importer API endpoint when handling import requests. A remote user can submit a crafted import request to overwrite the created_by field of an import file.
Exploitation requires CSV import capabilities and a valid API key, and user interaction is required.