Impact
The Importer API endpoint in Snipe-IT allows a user with CSV import permissions and a valid API key to overwrite the created_by value of an import file. This flaw permits an attacker to alter ownership metadata of imports, which can undermine audit trails and the integrity of asset tracking data.
Affected Systems
Grokability Snipe‑IT products are affected. Any release prior to version 8.6.1 is vulnerable; the issue was fixed in release 8.6.1.
Risk and Exploitability
The CVSS score of 5.7 categorizes the vulnerability as moderate. The EPSS score of < 1 % indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. The attack vector requires a valid API key and import privileges, so the threat primarily targets users with legitimate access or those who compromise an authorized credential. The impact is confined to metadata integrity rather than direct data or system compromise.
OpenCVE Enrichment