Missing Authorization in snipe-it - #VU145096
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in custom_fields_form.blade.php when rendering encrypted custom-field values in asset workflow forms. A remote user can open a corresponding asset form to disclose sensitive information.
The issue affects listbox, textarea, markdown-textarea, and text-backed date and datetime picker field types. In multi-company deployments, disclosure is limited to assets within the caller\'s company scope.