<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:25:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335951</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335951</link>
      <description>EUVD-2026-335951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335951</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55462</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55462</link>
      <description>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permissions would otherwise deny. This issue is fixed in version 8.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55462</guid>
    </item>
    <item>
      <title>GHSA-fc33-6w3q-538h — Snipe-IT has an authorization bypass on print inventory page</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fc33-6w3q-538h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;### Impact
An authenticated user with only `users.view` can open another user&amp;#39;s detail page and see assigned license, accessory, and consumable data even though the same account is denied direct access to the Licenses, Accessories, and Consumables modules. The leaked data includes software license names, purchase order/order values, accessory and consumable names, assignment notes, and purchase costs.&lt;/p&gt;
&lt;p&gt;### Attacker Model&lt;/p&gt;
&lt;p&gt;Authenticated user with only:&lt;/p&gt;
&lt;p&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ json
{&amp;#34;users.view&amp;#34;:&amp;#34;1&amp;#34;}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/p&gt;
&lt;p&gt;The attacker does not have:&lt;/p&gt;
&lt;p&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ json
{
  &amp;#34;licenses.view&amp;#34;: &amp;#34;1&amp;#34;,
  &amp;#34;accessories.view&amp;#34;: &amp;#34;1&amp;#34;,
  &amp;#34;consumables.view&amp;#34;: &amp;#34;1&amp;#34;,
  &amp;#34;assets.view&amp;#34;: &amp;#34;1&amp;#34;
}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/p&gt;
&lt;p&gt;### Affected Component&lt;/p&gt;
&lt;p&gt;-   `app/Http/Controllers/Users/UsersController.php`&lt;/p&gt;
&lt;p&gt;-   `resources/views/users/view.blade.php`&lt;/p&gt;
&lt;p&gt;-   `resources/views/users/print.blade.php`&lt;/p&gt;
&lt;p&gt;-   Endpoints:&lt;/p&gt;
&lt;p&gt;-   `GET /users/{user}`&lt;/p&gt;
&lt;p&gt;-   `GET /users/{user}/print`&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;`UsersController::show()` authorizes only viewing the user, then loads inventory relationships:&lt;/p&gt;
&lt;p&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ php
$this-&amp;gt;authorize(&amp;#39;view&amp;#39;, $user);&lt;/p&gt;
&lt;p&gt;$user = User::with([
    &amp;#39;consumables&amp;#39;,
    &amp;#39;accessories&amp;#39;,
    &amp;#39;licenses&amp;#39;,
    &amp;#39;userloc&amp;#39;,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;### Impact
An authenticated user with only `users.view` can open another user&amp;#39;s detail page and see assigned license, accessory, and consumable data even though the same account is denied direct access to the Licenses, Accessories, and Consumables modules. The leaked data includes software license names, purchase order/order values, accessory and consumable names, assignment notes, and purchase costs.&lt;/p&gt;
&lt;p&gt;### Attacker Model&lt;/p&gt;
&lt;p&gt;Authenticated user with only:&lt;/p&gt;
&lt;p&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ json
{&amp;#34;users.view&amp;#34;:&amp;#34;1&amp;#34;}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/p&gt;
&lt;p&gt;The attacker does not have:&lt;/p&gt;
&lt;p&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ json
{
  &amp;#34;licenses.view&amp;#34;: &amp;#34;1&amp;#34;,
  &amp;#34;accessories.view&amp;#34;: &amp;#34;1&amp;#34;,
  &amp;#34;consumables.view&amp;#34;: &amp;#34;1&amp;#34;,
  &amp;#34;assets.view&amp;#34;: &amp;#34;1&amp;#34;
}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/p&gt;
&lt;p&gt;### Affected Component&lt;/p&gt;
&lt;p&gt;-   `app/Http/Controllers/Users/UsersController.php`&lt;/p&gt;
&lt;p&gt;-   `resources/views/users/view.blade.php`&lt;/p&gt;
&lt;p&gt;-   `resources/views/users/print.blade.php`&lt;/p&gt;
&lt;p&gt;-   Endpoints:&lt;/p&gt;
&lt;p&gt;-   `GET /users/{user}`&lt;/p&gt;
&lt;p&gt;-   `GET /users/{user}/print`&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;`UsersController::show()` authorizes only viewing the user, then loads inventory relationships:&lt;/p&gt;
&lt;p&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ php
$this-&amp;gt;authorize(&amp;#39;view&amp;#39;, $user);&lt;/p&gt;
&lt;p&gt;$user = User::with([
    &amp;#39;consumables&amp;#39;,
    &amp;#39;accessories&amp;#39;,
    &amp;#39;licenses&amp;#39;,
    &amp;#39;userloc&amp;#39;,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fc33-6w3q-538h</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2073 — Snipe-IT: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Dateien zu manipulieren, um Sicherheitsvorkehrungen zu umgehen, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2073</guid>
    </item>
  </channel>
</rss>
