Authorization bypass through user-controlled key in snipe-it - #VU134511
Published: June 15, 2026
snipe-it
Detailed vulnerability description
The vulnerability allows a remote user to modify assets across company boundaries.
The vulnerability exists due to authorization bypass through user-controlled key in BulkAssetsController::update() when processing bulk asset update requests. A remote user can supply a company_id value from user input to modify assets across company boundaries.
The issue breaks multi-tenancy isolation for non-superadmin users.