Authorization bypass through user-controlled key in snipe-it - #VU145103
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Livewire importer at App\\Livewire\\Importer when loading Import records for the importer file list and preview. A remote user can select or enumerate other users\' Import records to disclose sensitive information.
User interaction is required to access the importer UI, and the disclosure is limited to preview data such as stored metadata, column headers, and the first CSV row. In multi-company deployments, the exposure can cross tenant boundaries.