Improper Check for Unusual or Exceptional Conditions in snipe-it - #VU145078

 

Improper Check for Unusual or Exceptional Conditions in snipe-it - #VU145078

Published: August 25, 2026


Vulnerability identifier: #VU145078
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to create a fraudulent acceptance record.

The vulnerability exists due to improper check for unusual or exceptional conditions in Account\\AcceptanceController::store() when handling acceptance evidence storage. A remote user can complete an acceptance flow during a silent storage write failure to create a fraudulent acceptance record.

The issue occurs on non-throwing filesystem drivers that return false on write failure, leaving acceptance metadata, action logs, and completion notifications generated even though the signature or PDF evidence files are absent from storage.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins