Authorization bypass through user-controlled key in snipe-it - CVE-2026-55694

 

Authorization bypass through user-controlled key in snipe-it - CVE-2026-55694

Published: August 14, 2026


Vulnerability identifier: #VU142577
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55694
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the EULA file access routes when handling requests for user EULA metadata and stored EULA files. A remote user can query another user\'s EULA metadata to obtain the secret filename and then request the file through the vulnerable profile route to disclose sensitive information.

Exploitation requires chaining an information disclosure in the /api/v1/users/{target_id}/eulas endpoint with an insecure direct object reference in the /account/stored-eula-file/{filename} route.


Affected software

snipe-it

How to mitigate CVE-2026-55694

Install security update from vendor's website.

snipe-it - update to 8.6.3

External References

Related Security Bulletins