Authorization bypass through user-controlled key in snipe-it - #VU145103

 

Authorization bypass through user-controlled key in snipe-it - #VU145103

Published: August 25, 2026


Vulnerability identifier: #VU145103
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the Livewire importer at App\\Livewire\\Importer when loading Import records for the importer file list and preview. A remote user can select or enumerate other users\' Import records to disclose sensitive information.

User interaction is required to access the importer UI, and the disclosure is limited to preview data such as stored metadata, column headers, and the first CSV row. In multi-company deployments, the exposure can cross tenant boundaries.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins