Authorization bypass through user-controlled key in snipe-it - #VU145082
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information across company boundaries.
The vulnerability exists due to incorrect authorization in ReportsController asset acceptance report endpoints when handling requests to view or export pending asset acceptances. A remote user can request the unaccepted assets report page or CSV export to disclose sensitive information across company boundaries.
Only Full Multiple Company Support instances are affected, and the disclosed data can include company names, asset details, and the display names of users holding pending checkout acceptances.