Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p68w-rgmg-3c2v | Snipe-IT Vulnerable to User Account Escalation via CSV Import |
Wed, 19 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. app/Importer/UserImporter.php applies the canEditAuthFields gate by unsetting username, email, password, and activated on the model, but app/Importer/ItemImporter.php sanitizeItemForUpdating() rebuilds the update array from the raw CSV row in $this->item, restoring the unauthorized values. The app/Http/Controllers/ImportController.php import path checks import permission but does not require users.edit. This issue is fixed in version 8.6.1. | |
| Title | Snipe-IT: User Account Escalation via CSV Import | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-19T19:18:33.675Z
Reserved: 2026-06-02T18:30:51.281Z
Link: CVE-2026-49976
No data.
Status : Received
Published: 2026-08-19T19:17:17.923
Modified: 2026-08-19T19:17:17.923
Link: CVE-2026-49976
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization
Github GHSA