Incorrect authorization in snipe-it - #VU145115

 

Incorrect authorization in snipe-it - #VU145115

Published: August 25, 2026


Vulnerability identifier: #VU145115
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to upload or delete file attachments on asset model records.

The vulnerability exists due to incorrect authorization in AssetModelPolicy file authorization and uploaded file controllers when handling file upload and delete requests for asset model attachments. A remote user can send crafted requests to asset model file endpoints to upload or delete shared model file attachments.

Under Full Multiple Company Support, asset models are not company-scoped, so the issue can affect model records across company boundaries.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins