CVE-2026-55469EPSS p46.4%

CVE-2026-55469CVE-2026-55469

snipeitapp / snipe-it

Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS0.59% probability of exploitation · percentile 46.4% · 2026-10-06T12:00:23Z
Last modified2026-07-14
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.