Executive brief
Snipe-IT is an open-source IT asset management system used by organizations to track hardware and software licenses. A security flaw in versions prior to 8.5.1 allows logged-in users to bypass security checks and view digital signature images stored in Amazon S3 storage. If an attacker knows the filename of a signature, they can generate a temporary link to view it without proper authorization, potentially exposing sensitive proof-of-acceptance records.
Technical details
A missing authorization check (CWE-862) exists in Snipe-IT's ActionlogController when handling signature image retrieval for S3-backed deployments. In affected versions, the code branch responsible for S3 storage returns a 5-minute signed URL before reaching the authorize() call that is correctly implemented for local file storage. An authenticated attacker who knows or guesses a signature filename can obtain a temporary signed S3 URL to view the image. This issue is resolved in version 8.5.1 (and noted as 8.6.1 in some documentation) by ensuring authorization checks occur before the S3 URL generation.
Affected products
- Grokability Snipe-IT < 8.5.1
Timeline
- 2026-06-13: advisory: GitHub Security Advisory GHSA-6mmj-jhqj-6c6q published
- 2026-07-08: disclosed: CVE-2026-55542 published to NVD