Authorization bypass through user-controlled key in snipe-it - #VU145082

 

Authorization bypass through user-controlled key in snipe-it - #VU145082

Published: August 25, 2026


Vulnerability identifier: #VU145082
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information across company boundaries.

The vulnerability exists due to incorrect authorization in ReportsController asset acceptance report endpoints when handling requests to view or export pending asset acceptances. A remote user can request the unaccepted assets report page or CSV export to disclose sensitive information across company boundaries.

Only Full Multiple Company Support instances are affected, and the disclosed data can include company names, asset details, and the display names of users holding pending checkout acceptances.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins