
🚨*CVE* CVE-2026-55474 Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-dir… https://www.cve.org/CVERecord?id=CVE-2026-55474 ----- Traducción: CVE-2026-55474 Sni… http://infoflow.cloud`
Post summary
CVE-2026-55474 exposes a privacy issue in Snipe‑IT's ActionlogController that concatenates a filename parameter into a private upload directory prior to version 8.5.0.

