Information Disclosure Vulnerability in Snipe-IT IT Asset Management System
CVE-2026-55694

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55694?

Snipe-IT, a popular IT asset and license management system, has a security issue affecting versions prior to 8.6.3. In this situation, a restricted user can exploit the API to request another user's randomized End User License Agreement (EULA) filename. This potentially allows unauthorized users to download sensitive signed files via the specific API endpoint. Although the access is prevented correctly under the primary route for stored EULA files, the lack of consistent ownership verification in specific controller functions creates this vulnerability. The issue has been patched in version 8.6.3, reinforcing user permission checks to prevent unauthorized access.

Affected Version(s)

snipe-it < 8.6.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.