Incorrect authorization in snipe-it - #VU145097
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in LicensesController::getExportLicensesCsv() when handling requests to export license data as CSV. A remote user can request the bulk CSV export to disclose sensitive information.
The exposed data consists of license product keys in cleartext, subject only to the standard FMCS company scope.