User Account Takeover Risk in Snipe-IT IT Asset Management Software
CVE-2026-49976
6.5MEDIUM
What is CVE-2026-49976?
A vulnerability in Snipe-IT allows a user with import permissions to manipulate CSV updates, potentially overwriting the email address of a non-admin user. This flaw can enable the attacker to request a password reset for the compromised account, effectively taking control of it. The vulnerability arises from a misconfiguration in the import process, where restrictions meant to protect user data are bypassed, particularly in versions prior to 8.6.1. The issue has been addressed in version 8.6.1, emphasizing the importance of updating to maintain security.
Affected Version(s)
snipe-it < 8.6.1
