User Account Takeover Risk in Snipe-IT IT Asset Management Software
CVE-2026-49976

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49976?

A vulnerability in Snipe-IT allows a user with import permissions to manipulate CSV updates, potentially overwriting the email address of a non-admin user. This flaw can enable the attacker to request a password reset for the compromised account, effectively taking control of it. The vulnerability arises from a misconfiguration in the import process, where restrictions meant to protect user data are bypassed, particularly in versions prior to 8.6.1. The issue has been addressed in version 8.6.1, emphasizing the importance of updating to maintain security.

Affected Version(s)

snipe-it < 8.6.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.