Impact
The flaw lies in Snipe‑IT's user import function, where a user granted only import rights can overwrite the email address of another non‑admin account. The importer clears authentication fields for authorization checks but subsequently restores the email field from the CSV, allowing an attacker to trigger a password reset and assume control of that account. This results in unprivileged users taking control of a non‑admin account, representing an authorization bypass (CWE‑863).
Affected Systems
All Snipe‑IT installations from the grokability vendor before version 8.6.1 are affected. Any user who can import CSV data in update mode is at risk, regardless of their current role or group membership.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting no known public exploit yet. Attackers only need to hold import permissions; the exploit path is straightforward and does not involve additional conditions or zero‑day techniques.
OpenCVE Enrichment
Github GHSA