---
id: CVE-2026-55469
title: Snipe-IT is an IT asset/license management system
summary: >-
  Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an
  authenticated user with import and assets.update permissions can place a path
  traversal string in an asset image field through CSV import and then trigger
  image deleti…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55469'
references:
  - url: >-
      https://github.com/grokability/snipe-it/commit/abc4363e8393b29a5566b8c50144426af72bbc97
    label: security-advisories@github.com
  - url: 'https://github.com/grokability/snipe-it/releases/tag/v8.6.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-xr9m-gphc-9p63
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00589
epssPercentile: 0.45799
ingestedAt: '2026-07-11T20:15:26.621Z'
---

## Overview

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
