CVE-2026-55462: Snipe-IT: Authorization bypass on print inventory page
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55462?
The severity of CVE-2026-55462 is medium, rated at 4.3.
How do I fix CVE-2026-55462?
To fix CVE-2026-55462, upgrade to Snipe-IT version 8.6.2 or later.
What does CVE-2026-55462 affect?
CVE-2026-55462 affects the Snipe-IT application, specifically the UsersController::show() and printInventory() functions.
Who is vulnerable to CVE-2026-55462?
Authenticated users with limited permissions can exploit CVE-2026-55462 to access unauthorized inventory information.
What type of vulnerability is CVE-2026-55462?
CVE-2026-55462 is an authorization bypass vulnerability.