CVE-2026-55703 - Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET
Brief
CVE ID : CVE-2026-55703
Published : Aug. 19, 2026, 6:23 p. m.
- 45 minutes ago
Description : Snipe-IT is an IT asset/license management system. Prior to 8.
- 3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController. php show() renders the record without authorize(), while company-scoped route-model binding only prevents access to other companies.
Disclosed fields include asset tags, suppliers, purchase costs, notes, and dates. This issue is fixed in version 8.
- 3.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
