Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another user or asset. This issue is fixed in version 8.6.2.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an incorrect authorization check in the legacy single‑seat license check‑in API of Snipe‑IT. The system authorizes the operation using the assign‑license permission instead of the intended check‑in permission, enabling a user who can grant licenses but normally cannot unassign to another user or asset. This allows an unauthorized transfer of license ownership and bypasses audit trails. The weakness is a classic example of improper privilege escalation (CWE‑863).

Affected Systems

Snipe‑IT asset and license management from grokability is affected. Any installation running a version earlier than v8.6.2 is vulnerable, regardless of operating system or deployment method.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1% indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would typically use the legacy API endpoint, which requires network access to the Snipe‑IT instance and authentication as a user with assign‑license permissions. While network segmentation can reduce exposure, the risk of an insider user or compromised internal account remains, especially if that account holds the assign‑license role.

Generated by OpenCVE AI on July 26, 2026 at 13:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Snipe‑IT version 8.6.2 or newer to apply the fixed permission check.
  • If an upgrade cannot be performed immediately, block or disable the legacy check‑in API route until the system can be patched.
  • Reassess and restrict the assign‑license permission role so that only trusted users retain it, thereby limiting the attack surface.

Generated by OpenCVE AI on July 26, 2026 at 13:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another user or asset. This issue is fixed in version 8.6.2.
Title Snipe-IT: Incorrect permission for legacy license checkin API
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-10T20:57:59.427Z

Reserved: 2026-06-16T22:28:27.061Z

Link: CVE-2026-55479

cve-icon Vulnrichment

Updated: 2026-07-10T20:46:17.308Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T13:15:17Z

Weaknesses