Improper Authorization in snipe-it - #VU134512
Published: June 15, 2026
snipe-it
Detailed vulnerability description
The vulnerability allows a remote attacker to delete files attached to assets.
The vulnerability exists due to improper authorization in the file deletion endpoint when handling file deletion requests for asset attachments. A remote attacker can send a crafted request to delete files attached to any asset in the system.
The issue affects both the web and API controllers.