Improper Enforcement of Behavioral Workflow in snipe-it - #VU145105

 

Improper Enforcement of Behavioral Workflow in snipe-it - #VU145105

Published: August 25, 2026


Vulnerability identifier: #VU145105
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-841
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify asset custody records and bypass checkout workflow restrictions.

The vulnerability exists due to improper enforcement of behavioral workflow in the PATCH /api/v1/hardware/{asset_id} asset update endpoint when processing assignment fields in asset update requests. A remote user can submit a specially crafted PATCH request with assigned_user, assigned_asset, or assigned_location fields to modify asset custody records and bypass checkout workflow restrictions.

The issue can be exploited by an authenticated account with asset view and edit permissions but without checkout or check-in permissions, and it can overwrite an existing assignment without an intervening check-in.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins