Race condition in snipe-it - #VU145083

 

Race condition in snipe-it - #VU145083

Published: August 25, 2026


Vulnerability identifier: #VU145083
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to corrupt asset checkout audit history and inflate checkout counters.

The vulnerability exists due to concurrent execution using shared resource with improper synchronization in Api\\AssetsController::checkout(), Assets\\AssetCheckoutController::store(), and related asset checkout paths when handling concurrent checkout requests for the same asset. A remote privileged user can send two concurrent checkout requests for the same asset to corrupt asset checkout audit history and inflate checkout counters.

Successful exploitation requires precise timing and an asset that is eligible for checkout.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins