Incorrect authorization in snipe-it - #VU145114

 

Incorrect authorization in snipe-it - #VU145114

Published: August 25, 2026


Vulnerability identifier: #VU145114
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify data associations.

The vulnerability exists due to incorrect authorization in PredefinedKitsController update and storeModel endpoints when handling requests to attach licenses, consumables, accessories, or asset models to predefined kits. A remote user can send a specially crafted request referencing an object they cannot directly read to disclose sensitive information and modify data associations.

The relation index leaks the attached object\'s name back to the caller, and no user interaction is required.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins