THREAT OPS › Threat News › [GHSA] GHSA-fc33-6w3q-538h (medium) — Snipe-IT has an authorization bypass on print inventory page
[GHSA] GHSA-fc33-6w3q-538h (medium) — Snipe-IT has an authorization bypass on print inventory page
GHSA-fc33-6w3q-538h Severity: medium CVE: CVE-2026-55462
Snipe-IT has an authorization bypass on print inventory page
### Impact An authenticated user with only `users.view` can open another user's detail page and see assigned license, accessory, and consumable data even though the same account is denied direct access to the Licenses, Accessories, and Consumables modules. The leaked data include
Indicators of compromise
- CVE-2026-55462cve
Original source: https://github.com/advisories/GHSA-fc33-6w3q-538h