Vulnerability Description
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file branch. Version 8.6.1 contains a patch.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snipeitapp | Snipe-It | < 8.6.0 |
Related Weaknesses (CWE)
References
- https://github.com/grokability/snipe-it/commit/ded6515cbc27a28f07395da318483c2e9Patch
- https://github.com/grokability/snipe-it/security/advisories/GHSA-6mmj-jhqj-6c6qPatchVendor Advisory
FAQ
What is CVE-2026-55542?
CVE-2026-55542 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users...
How severe is CVE-2026-55542?
CVE-2026-55542 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55542?
Check the references section above for vendor advisories and patch information. Affected products include: Snipeitapp Snipe-It.