Improper access control in snipe-it - CVE-2026-55462
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the user detail and print inventory endpoints when handling requests for another user\'s record. A remote user can request the affected pages to disclose sensitive information.
The issue affects accounts that have only the users.view permission but lack direct access to the licenses, accessories, and consumables modules.