Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.
Published: 2026-07-10
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises because the UsersController::show() and printInventory() actions perform insufficient authorization checks before loading and rendering license, accessory, and consumable relationships. An authenticated user with only the users.view permission can access the print inventory page and view inventory and cost/order metadata that should normally be restricted by more specific permission modules.

Affected Systems

All installations of Snipe‑IT running a release older than version 8.6.2 are affected. This includes deployments on web servers, containers, and on‑premises environments where the software has not yet been updated to the fixed release.

Risk and Exploitability

With a CVSS score of 4.3 the vulnerability is considered moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is straightforward authenticated access: a user who has only the users.view permission can trigger the print inventory page and extract the data without additional privileges or techniques.

Generated by OpenCVE AI on July 29, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.6.2 or later
  • Restrict the print inventory functionality to roles with higher permissions
  • Re‑evaluate and remove the users.view permission for users who do not require inventory data access

Generated by OpenCVE AI on July 29, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.
Title Snipe-IT: Authorization bypass on print inventory page
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-13T15:01:17.917Z

Reserved: 2026-06-16T22:10:37.608Z

Link: CVE-2026-55462

cve-icon Vulnrichment

Updated: 2026-07-13T15:01:07.525Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:30:05Z

Weaknesses