Incorrect authorization in snipe-it - #VU145107
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information across company boundaries.
The vulnerability exists due to incorrect authorization in the /hardware/requested requested-assets listing endpoint when handling a GET request with FMCS enabled. A remote user can send an unmodified GET request to disclose sensitive information across company boundaries.
Only FMCS-enabled installations are vulnerable, and the endpoint may expose the requested asset name, the requester\'s display name and profile link, the location, and the expected check-in date from other companies\' pending requests.