Incorrect calculation in snipe-it - #VU145075
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to modify asset request counters and misrepresent pending demand.
The vulnerability exists due to incorrect calculation in checkout-request endpoints when processing duplicate request submissions and cancel requests without an active checkout request. A remote user can send repeated crafted requests to modify asset request counters and misrepresent pending demand.
The issue affects both the API and sibling web checkout-request paths, and repeated calls can drive the counter below zero or inflate the admin queue.