Impact
The flaw in Snipe‑IT’s legacy single‑seat license check‑in API causes the system to authenticate the action with the assign‑license permission rather than the intended check‑in permission. This allows a user who can grant licenses—but normally cannot unassign them—to call the legacy endpoint and reclaim a license seat that belongs to another user or asset. The resulting unauthorized transfer is a classic improper authorization vulnerability (CWE‑863).
Affected Systems
Snipe‑IT deployments of the grokability repository running any version earlier than 8.6.2 are affected, regardless of underlying platform or hosting environment. The issue exists in the legacy check‑in endpoint that was replaced in the 8.6.2 release.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1 % implies a very low likelihood of exploitation today. The vulnerability is not in the CISA KEV catalog. Attackers would need network access to a V‑host running Snipe‑IT, authentication as a user with the grant‑license permission, and knowledge of the legacy endpoint URL. While external attackers have limited reach, the flaw is more concerning for internal or compromised accounts that hold the assign‑license role.
OpenCVE Enrichment