PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49976 grokability CVE debrief

CVE-2026-49976 debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:17.923Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects Snipe-IT versions prior to 8.6.1, allowing users with import permissions to overwrite email addresses of non-admin users via CSV import, potentially leading to account takeovers. Defenders should assess exposure, restrict import permissions, and prioritize upgrading to version 8.6.1.

Vendor
grokability
Product
snipe-it
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-09-09
Advisory published
2026-08-19
Advisory updated
2026-09-09

Who should care

Defenders managing Snipe-IT deployments, especially those with user import permissions enabled, should assess exposure and prioritize verification and remediation efforts. This includes IT asset managers, security teams, and operators responsible for maintaining Snipe-IT systems. They should verify the version of Snipe-IT in use, restrict import permissions to trusted users, and monitor for suspicious activity related to password resets.

Why it matters

CVE-2026-49976 allows users with import permissions in Snipe-IT to overwrite email addresses of non-admin users via CSV import, potentially leading to account takeovers. Defenders should verify exposure, restrict import permissions, and prioritize upgrading to version 8.6.1.

  • Potential account takeover by users with import permissions
  • Need for verification of Snipe-IT version and exposure
  • Priority on upgrading to version 8.6.1 or later
  • Monitoring for suspicious activity related to password resets

Technical summary

In Snipe-IT versions prior to 8.6.1, a user with import permission can use CSV update mode to overwrite the email address of a non-admin user. This can be used to request a password reset and gain control of that account. The issue is fixed in version 8.6.1. The vulnerability exists due to improper sanitization of user input in the CSV import functionality, allowing attackers to modify user email addresses. Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user import permissions are utilized, and assess the need for an upgrade to version 8.6.1.

Defensive priority

Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user import permissions are utilized, and assess the need for an upgrade to version 8.6.1.

Recommended defensive actions

  • Verify Snipe-IT version and assess exposure
  • Restrict import permissions to trusted users
  • Monitor for suspicious password reset requests
  • Upgrade to Snipe-IT version 8.6.1 or later
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Snipe-IT versions prior to 8.6.1, where a user with import permission can overwrite the email address of a non-admin user via CSV update mode and then request a password reset to gain control of that account.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49976 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49976

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49976 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49976

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.