Improper access control in snipe-it - CVE-2026-55472
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the API endpoint for creating locations when handling location creation requests with a parent location from a different company. A remote user can submit a crafted API request to disclose sensitive information.
Only instances with Full Multiple Companies Support and scope_locations_fmcs enabled are vulnerable. The equivalent Web flow correctly rejects the same relationship.