Incorrect authorization in snipe-it - #VU145097

 

Incorrect authorization in snipe-it - #VU145097

Published: August 25, 2026


Vulnerability identifier: #VU145097
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in LicensesController::getExportLicensesCsv() when handling requests to export license data as CSV. A remote user can request the bulk CSV export to disclose sensitive information.

The exposed data consists of license product keys in cleartext, subject only to the standard FMCS company scope.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins