What is CVE-2026-55694?
CVE-2026-55694 in Snipe-IT before version 8.6.3 allows a restricted user to obtain another user's signed EULA file by requesting the randomized filename via `/api/v1/users/{target_id}/eulas` and then downloading it. Upgrading to version 8.6.3 or later is recommended to address this vulnerability.
Azərbaycanca: CVE-2026-55694 Snipe-IT aktiv idarəetmə sistemində 8.6.3 versiyasından əvvəlki versiyalarda məhdud istifadəçilərə digər istifadəçilərin imzalanmış EULA fayllarını əldə etməyə imkan verir. Zəiflik `/api/v1/users/{target_id}/eulas` endpoint-i vasitəsilə təsadüfi fayl adını tapıb, sonra faylı yükləməyə şərait yaradır. Sistemin 8.6.3 və ya daha yeni versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of confidential data can be exposed by CVE-2026-55694 in Snipe-IT?
The vulnerability allows a restricted user to obtain another user's signed EULA file.
To which version should Snipe-IT be upgraded to remediate CVE-2026-55694?
Upgrading to version 8.6.3 or later is recommended to address this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.