{"id":"CVE-2026-55694","aliases":["GHSA-3hgv-jr5j-cg9x"],"url":"https://o3.security/vulnerability/CVE-2026-55694","summary":"Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover","details":"### Impact\nAn attacker can completely bypass file-name randomization security and without authorization download confidential, signed EULA files belonging to any other user across the application.\n\n### Steps to Reproduce:\n1. Log in as a restricted user.\n2. Send a GET request to /api/v1/users/{target_id}/eulas (where target_id belongs to a restricted/denied user).\n3. Observe the response leaks the secret EULA filename (e.g., eula-xxx.pdf).\n4. Attempt to access this file via the main route: GET /stored-eula-file/{filename} (This will correctly return 403 Forbidden).\n5. Now, access the file via the vulnerable profile route: GET /account/stored-eula-file/{filename}.\n6. Observe that the server returns a 200 OK and successfully downloads the target user's secret EULA file.\n\n### Patches\nFixed in https://github.com/grokability/snipe-it/commit/f15d78621b003be30ac114ba68626683894935ef","published":"2026-08-19T18:28:22.109Z","modified":"2026-10-02T03:47:28.735785585Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"snipe/snipe-it","fixedVersion":"8.6.3"}],"fix":{"url":"https://github.com/grokability/snipe-it/commit/f15d78621b003be30ac114ba68626683894935ef","label":"grokability/snipe-it@f15d786"},"references":[{"type":"WEB","url":"https://github.com/grokability/snipe-it/releases/tag/v8.6.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55694.json"},{"type":"ADVISORY","url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-3hgv-jr5j-cg9x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55694"},{"type":"FIX","url":"https://github.com/grokability/snipe-it/commit/f15d78621b003be30ac114ba68626683894935ef"},{"type":"PACKAGE","url":"https://github.com/grokability/snipe-it"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T03:47:28.735785585Z"}}