Path traversal in snipe-it - CVE-2026-55469

 

Path traversal in snipe-it - CVE-2026-55469

Published: August 14, 2026


Vulnerability identifier: #VU142564
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55469
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to delete arbitrary files on the server filesystem.

The vulnerability exists due to path traversal in the CSV import image field when processing imported asset records and triggering image deletion. A remote attacker can inject a path traversal string into the image field via CSV import to delete arbitrary files on the server filesystem.

Exploitation requires the import and assets.update permissions.


Affected software

snipe-it

How to mitigate CVE-2026-55469

Install security update from vendor's website.

snipe-it - update to 8.6.2

External References

Related Security Bulletins