Missing Authorization in snipe-it - #VU145099
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to tamper with asset ownership records and inject fraudulent audit-log entries.
The vulnerability exists due to missing authorization in the legacy asset-history CSV importer (`POST /hardware/history`, `AssetsController::postImportHistory`) when processing a multipart POST request containing a `user_import_csv` file. A remote user can submit a crafted CSV file to tamper with asset ownership records and inject fraudulent audit-log entries.
In multi-company deployments, the issue can affect assets belonging to other companies and bypass normal checkout policy and company scoping.