Input validation error in snipe-it - #VU145108

 

Input validation error in snipe-it - #VU145108

Published: August 25, 2026


Vulnerability identifier: #VU145108
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify inventory assignment records and cause inconsistent downstream processing.

The vulnerability exists due to improper input validation in the API checkout endpoints when processing checkout requests that reference soft-deleted users, assets, or locations. A remote user can send a specially crafted checkout request to modify inventory assignment records and cause inconsistent downstream processing.

Exploitation requires the relevant checkout permission for the affected resource.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins