Incorrect authorization in snipe-it - #VU145101
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the location print endpoints and print template when handling requests to location print views. A remote user can request a printassigned or printallassigned endpoint for a location to disclose sensitive information.
Instances that grant location view permission but deny view permission for related users, assets, accessories, consumables, or components are particularly affected.