CVE-2026-55703
EUVD-2026-6262719.08.2026, 19:17
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() renders the record without authorize(), while company-scoped route-model binding only prevents access to other companies. Disclosed fields include asset tags, suppliers, purchase costs, notes, and dates. This issue is fixed in version 8.6.3.EnginsightAwaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration