Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘 Packagist
Not in CISA KEV

CVE-2026-55694 — snipe/snipe-it

Fix: grokability/snipe-it@f15d786

CVE-2026-55694 is a CWE-639 vulnerability in snipe/snipe-it. A fix is available for snipe/snipe-it — see the affected versions and patch details below.

Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover

Also known asGHSA-3hgv-jr5j-cg9x
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Oct 3, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-55694.

EPSS Exploitation Probability

via FIRST.org ↗
0.3%probability of exploitation in next 30 days
Lower Risk+0.05%
Lower risk than most CVEs19th percentile — riskier than 19% of all scored CVEsHighest risk
0.00%0.26%0.53%0.79%0.2%0.3%Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

1 pkg affected
🐘snipe/snipe-it

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Impact

An attacker can completely bypass file-name randomization security and without authorization download confidential, signed EULA files belonging to any other user across the application.

Steps to Reproduce:

  1. Log in as a restricted user.
  2. Send a GET request to /api/v1/users/{target_id}/eulas (where target_id belongs to a restricted/denied user).
  3. Observe the response leaks the secret EULA filename (e.g., eula-xxx.pdf).
  4. Attempt to access this file via the main route: GET /stored-eula-file/{filename} (This will correctly return 403 Forbidden).
  5. Now, access the file via the vulnerable profile route: GET /account/stored-eula-file/{filename}.
  6. Observe that the server returns a 200 OK and successfully downloads the target user's secret EULA file.

Patches

Fixed in https://github.com/grokability/snipe-it/commit/f15d78621b003be30ac114ba68626683894935ef

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistsnipe/snipe-itall versions8.6.3composer require snipe/snipe-it:^8.6.3

Affected Products

1 product · 1 configurations
Application
snipe-itsnipeitapp
< 8.6.3
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for snipe/snipe-it, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update snipe/snipe-it to 8.6.3 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-55694 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Frequently Asked Questions

### Impact An attacker can completely bypass file-name randomization security and without authorization download confidential, signed EULA files belonging to any other user across the application. ### Steps to Reproduce: 1. Log in as a restricted user. 2. Send a GET request to /api/v1/users/{target_id}/eulas (where target_id belongs to a restricted/denied user). 3. Observe the response leaks the secret EULA filename (e.g., eula-xxx.pdf). 4. Attempt to access this file via the main route: GET /stored-eula-file/{filename} (This will correctly return 403 Forbidden). 5. Now, access the file via t
O3 Security · Impact-Aware SCA

Is CVE-2026-55694 in your dependencies?

Find it across Packagist, including transitive dependencies.

CVE-2026-55694: Fixed in 8.6.3 | O3 Security