Incorrect authorization in snipe-it - #VU145114
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data associations.
The vulnerability exists due to incorrect authorization in PredefinedKitsController update and storeModel endpoints when handling requests to attach licenses, consumables, accessories, or asset models to predefined kits. A remote user can send a specially crafted request referencing an object they cannot directly read to disclose sensitive information and modify data associations.
The relation index leaks the attached object\'s name back to the caller, and no user interaction is required.