Improper access control in snipe-it - CVE-2026-55462

 

Improper access control in snipe-it - CVE-2026-55462

Published: August 14, 2026


Vulnerability identifier: #VU142567
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55462
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the user detail and print inventory endpoints when handling requests for another user\'s record. A remote user can request the affected pages to disclose sensitive information.

The issue affects accounts that have only the users.view permission but lack direct access to the licenses, accessories, and consumables modules.


Affected software

snipe-it

How to mitigate CVE-2026-55462

Install security update from vendor's website.

snipe-it - update to 8.6.1

External References

Related Security Bulletins