THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fc33-6w3q-538h (medium) — Snipe-IT has an authorization bypass on print inventory page

[GHSA] GHSA-fc33-6w3q-538h (medium) — Snipe-IT has an authorization bypass on print inventory page

medgithub_advisoriesPublished 2026-08-28

GHSA-fc33-6w3q-538h Severity: medium CVE: CVE-2026-55462

Snipe-IT has an authorization bypass on print inventory page

### Impact An authenticated user with only `users.view` can open another user's detail page and see assigned license, accessory, and consumable data even though the same account is denied direct access to the Licenses, Accessories, and Consumables modules. The leaked data include

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fc33-6w3q-538h