Impact
The vulnerability allows an attacker to create a child location under a parent location belonging to a different company when Full Multiple Companies Support and the scope_locations_fmcs feature are enabled in Snipe-IT. The API location creation endpoint detects the mismatch but does not abort the request, resulting in a location being created with a parent from an unrelated company. This bypasses the intended company boundary checks and can lead to unauthorized placement of assets or misleading inventory data. The weakness is classified as CWE-863.
Affected Systems
Vulnerable versions are Snipe-IT releases prior to 8.6.2 when Full Multiple Companies Support affected product is the Snipe-IT asset management system developed by Grokability, with the specific issue fixed in release v8.6.2.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate. EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation data. The attack appears to occur via the authenticated location-creation API endpoint; therefore, the attacker must possess sufficient permissions to create locations. Based on the description, it is inferred that the attack vector is via authorized API usage, and the vulnerability essentially allows circumventing company boundary validation, potentially leading to data integrity violations across company partitions.
OpenCVE Enrichment