Improper access control in snipe-it - #VU134513
Published: June 15, 2026
snipe-it
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in S3 signature image retrieval when generating a temporary URL for a known signature filename. A remote user can request a signed S3 URL for another user's signature image to disclose sensitive information.
This issue affects S3-backed deployments and requires knowledge of a signature filename.