What is CVE-2026-49976?
A vulnerability in Snipe-IT, an IT asset management system, allows a user with import permission to overwrite a non-admin user's email via CSV update mode and then hijack the account through password reset. Versions prior to 8.6.1 are affected, and an immediate update is recommended.
Azərbaycanca: Snipe-IT aktiv idarəetmə sistemində CVE-2026-49976 zəifliyi aşkar edilib. Bu zəiflik `import` icazəsi olan istifadəçiyə CSV yeniləmə rejimi vasitəsilə qeyri-admin istifadəçinin e-poçt ünvanını dəyişərək parol sıfırlama yolu ilə həmin hesabı ələ keçirməyə imkan verir. 8.6.1 versiyasından əvvəlki versiyalar təsirlənir, dərhal yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which users can exploit CVE-2026-49976 in Snipe-IT?
Users with `import` permission can exploit this vulnerability.
To which version of Snipe-IT should users update to protect against CVE-2026-49976?
Users should update to version 8.6.1 or later, as versions prior to 8.6.1 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.