Impact
A vulnerability exists in the Kits API of the Snipe‑IT asset management system. The POST /api/v1/kits/{kit_id}/licenses endpoint verifies kit edit permissions but does not check whether the caller is authorized to access the referenced license. As a result, a user who has only kit‑editing rights can bind a license that the user would normally not be able to access or manage. The weakness is an access‑control flaw (CWE‑639).
Affected Systems
The issue affects all installations of grokability:snipe‑it version 8.6.1 and older. The problem is fixed in release 8.6.2 and later; the correct version range to patch is any version less than 8.6.2.
Risk and Exploitability
Based on the description, the likely attack vector is a network‑based API call that an authenticated user can perform from the web interface or API client. The attacker must have kit‑edit permissions but does not need higher privileges. Once the license is bound, the user may gain additional access to the license’s details. The CVSS score of 5.3 indicates moderate severity, the EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. This low EPSS suggests that exploitation is unlikely, but the impact in environments where kit‑edit rights are granted is sufficient.
OpenCVE Enrichment