Incorrect authorization in snipe-it - #VU145115
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to upload or delete file attachments on asset model records.
The vulnerability exists due to incorrect authorization in AssetModelPolicy file authorization and uploaded file controllers when handling file upload and delete requests for asset model attachments. A remote user can send crafted requests to asset model file endpoints to upload or delete shared model file attachments.
Under Full Multiple Company Support, asset models are not company-scoped, so the issue can affect model records across company boundaries.