Authorization bypass through user-controlled key in snipe-it - #VU142575
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to modify records across company boundaries and send reminder emails to users in other companies.
The vulnerability exists due to authorization bypass through user-controlled key in checkout-acceptance report actions when handling crafted requests referencing sequential acceptance IDs under full multiple company support. A remote user can send a specially crafted request to modify records across company boundaries and send reminder emails to users in other companies.
Exploitation requires the reports.view permission and full multiple company support to be enabled.