CVE-2026-55542Low▾ SunlitSnipe-IT's S3 signature image retrieval lacks authorization before temporary URL
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
Snipe-IT S3 signature image retrieval lacks authorization before temporary URL.
On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the authorize() call used by the local-file branch.
routes/web.php:135-143; app/Http/Controllers/ActionlogController.php:16-44; app/Http/Controllers/Account/AcceptanceController.php:160,175; app/Listeners/LogListener.php:56; app/Http/Transformers/ActionlogsTransformer.php:188
Patched in https://github.com/grokability/snipe-it/commit/ded6515cbc27a28f07395da318483c2e96263259
Disclosed by Ikaro tiagonas
snipe/snipe-it <= 8.5.0Upgrade to a patched release:
snipe/snipe-it 8.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55476MediumSnipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
CVE-2026-55703Medium· 4.3Snipe-IT is an IT asset/license management system
CVE-2026-48492MediumSnipe-IT's selectlist visibility is too permissive
CVE-2026-49976Medium· 6.5Snipe-IT is an IT asset/license management system
CVE-2026-50550Medium· 5.8Snipe-IT is an IT asset/license management system
CVE-2026-55483MediumSnipe-IT is an IT asset/license management system