Missing Authorization in snipe-it - #VU145099

 

Missing Authorization in snipe-it - #VU145099

Published: August 25, 2026


Vulnerability identifier: #VU145099
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to tamper with asset ownership records and inject fraudulent audit-log entries.

The vulnerability exists due to missing authorization in the legacy asset-history CSV importer (`POST /hardware/history`, `AssetsController::postImportHistory`) when processing a multipart POST request containing a `user_import_csv` file. A remote user can submit a crafted CSV file to tamper with asset ownership records and inject fraudulent audit-log entries.

In multi-company deployments, the issue can affect assets belonging to other companies and bypass normal checkout policy and company scoping.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins