<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:25:31.218255+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335951</id>
    <title>EUVD-2026-335951</title>
    <updated>2026-10-06T09:25:31.221465+00:00</updated>
    <content>EUVD-2026-335951</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55462</id>
    <title>fkie_cve-2026-55462</title>
    <updated>2026-10-06T09:25:31.221512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fc33-6w3q-538h</id>
    <title>GHSA-fc33-6w3q-538h — Snipe-IT has an authorization bypass on print inventory page</title>
    <updated>2026-10-06T09:25:31.221573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: snipe/snipe-it</p>
<p>### Impact
An authenticated user with only `users.view` can open another user's detail page and see assigned license, accessory, and consumable data even though the same account is denied direct access to the Licenses, Accessories, and Consumables modules. The leaked data includes software license names, purchase order/order values, accessory and consumable names, assignment notes, and purchase costs.</p>
<p>### Attacker Model</p>
<p>Authenticated user with only:</p>
<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ json
{"users.view":"1"}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p>
<p>The attacker does not have:</p>
<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ json
{
  "licenses.view": "1",
  "accessories.view": "1",
  "consumables.view": "1",
  "assets.view": "1"
}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p>
<p>### Affected Component</p>
<p>-   `app/Http/Controllers/Users/UsersController.php`</p>
<p>-   `resources/views/users/view.blade.php`</p>
<p>-   `resources/views/users/print.blade.php`</p>
<p>-   Endpoints:</p>
<p>-   `GET /users/{user}`</p>
<p>-   `GET /users/{user}/print`</p>
<p>### Root Cause</p>
<p>`UsersController::show()` authorizes only viewing the user, then loads inventory relationships:</p>
<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ php
$this-&gt;authorize('view', $user);</p>
<p>$user = User::with([
    'consumables',
    'accessories',
    'licenses',
    'userloc',…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fc33-6w3q-538h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073</id>
    <title>WID-SEC-W-2026-2073 — Snipe-IT: Mehrere Schwachstellen</title>
    <updated>2026-10-06T09:25:31.221663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073"/>
  </entry>
</feed>
