PatchSiren cyber security CVE debrief
CVE-2026-49976 grokability CVE debrief
CVE-2026-49976 debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:17.923Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects Snipe-IT versions prior to 8.6.1, allowing users with import permissions to overwrite email addresses of non-admin users via CSV import, potentially leading to account takeovers. Defenders should assess exposure, restrict import permissions, and prioritize upgrading to version 8.6.1.
- Vendor
- grokability
- Product
- snipe-it
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-09
Who should care
Defenders managing Snipe-IT deployments, especially those with user import permissions enabled, should assess exposure and prioritize verification and remediation efforts. This includes IT asset managers, security teams, and operators responsible for maintaining Snipe-IT systems. They should verify the version of Snipe-IT in use, restrict import permissions to trusted users, and monitor for suspicious activity related to password resets.
Why it matters
CVE-2026-49976 allows users with import permissions in Snipe-IT to overwrite email addresses of non-admin users via CSV import, potentially leading to account takeovers. Defenders should verify exposure, restrict import permissions, and prioritize upgrading to version 8.6.1.
- Potential account takeover by users with import permissions
- Need for verification of Snipe-IT version and exposure
- Priority on upgrading to version 8.6.1 or later
- Monitoring for suspicious activity related to password resets
Technical summary
In Snipe-IT versions prior to 8.6.1, a user with import permission can use CSV update mode to overwrite the email address of a non-admin user. This can be used to request a password reset and gain control of that account. The issue is fixed in version 8.6.1. The vulnerability exists due to improper sanitization of user input in the CSV import functionality, allowing attackers to modify user email addresses. Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user import permissions are utilized, and assess the need for an upgrade to version 8.6.1.
Defensive priority
Defenders should prioritize verifying exposure in Snipe-IT deployments, especially where user import permissions are utilized, and assess the need for an upgrade to version 8.6.1.
Recommended defensive actions
- Verify Snipe-IT version and assess exposure
- Restrict import permissions to trusted users
- Monitor for suspicious password reset requests
- Upgrade to Snipe-IT version 8.6.1 or later
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Snipe-IT versions prior to 8.6.1, where a user with import permission can overwrite the email address of a non-admin user via CSV update mode and then request a password reset to gain control of that account.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49976 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49976
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49976 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49976
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/commit/dd4117bd5be59766c22767717ec403dfdece1e19
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/pull/19072
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/releases/tag/v8.6.1
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-p68w-rgmg-3c2v
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.