CVE-2026-55703

Summary

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() renders the record without authorize(), while company-scoped route-model binding only prevents access to other companies. Disclosed fields include asset tags, suppliers, purchase costs, notes, and dates. This issue is fixed in version 8.6.3.

Affected Software

VendorProductVersion RangeStatus
grokabilitysnipe-it< 8.6.3affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization

References