Impact
The flaw arises because the UsersController::show() and printInventory() actions perform insufficient authorization checks before loading and rendering license, accessory, and consumable relationships. An authenticated user with only the users.view permission can access the print inventory page and view inventory and cost/order metadata that should normally be restricted by more specific permission modules.
Affected Systems
All installations of Snipe‑IT running a release older than version 8.6.2 are affected. This includes deployments on web servers, containers, and on‑premises environments where the software has not yet been updated to the fixed release.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is considered moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is straightforward authenticated access: a user who has only the users.view permission can trigger the print inventory page and extract the data without additional privileges or techniques.
OpenCVE Enrichment