Information Disclosure Vulnerability in Snipe-IT IT Asset Management System
CVE-2026-55694
7.1HIGH
What is CVE-2026-55694?
Snipe-IT, a popular IT asset and license management system, has a security issue affecting versions prior to 8.6.3. In this situation, a restricted user can exploit the API to request another user's randomized End User License Agreement (EULA) filename. This potentially allows unauthorized users to download sensitive signed files via the specific API endpoint. Although the access is prevented correctly under the primary route for stored EULA files, the lack of consistent ownership verification in specific controller functions creates this vulnerability. The issue has been patched in version 8.6.3, reinforcing user permission checks to prevent unauthorized access.
Affected Version(s)
snipe-it < 8.6.3
