Incorrect authorization in snipe-it - #VU145093

 

Incorrect authorization in snipe-it - #VU145093

Published: August 25, 2026


Vulnerability identifier: #VU145093
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to obtain an admin API token and access privileged API data.

The vulnerability exists due to improper access control in the /oauth/clients routes when handling OAuth client management requests and subsequent OAuth consent flows. A remote user can register an OAuth client with an attacker-controlled redirect URI and trick an admin into approving the consent screen to obtain an admin API token and access privileged API data.

User interaction is required for an admin to approve the OAuth consent screen, and the resulting bearer token inherits the approving admin\'s API permissions.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins