A AegiFlow
HIGHCVSS 7.1EPSS 0.2%

CVE-2026-55694

CVE-2026-55694 updated by NVD

Published
2026-08-19
Modified
2026-09-11
EPSS percentile
15%
Sources
github-advisory, nvd

Summary

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eula-file/{filename}. The primary /stored-eula-file/{filename} route correctly denies access, but app/Http/Controllers/ProfileController.php and app/Http/Controllers/Api/UsersController.php do not consistently enforce ownership and target-user authorization. This issue is fixed in version 8.6.3.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistsnipe/snipe-it8.6.3

Remediation: Upgrade to 8.6.3 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.