Impact
Snipe‑IT, an IT asset management system, prior to version 8.6.2 allowed the unaccepted‑assets delete endpoint to accept a global identifier and delete a pending CheckoutAcceptance record without checking whether the authenticated user had access to the checkoutable asset. This permits a user with reports.view to delete a record belonging to another company, thereby compromising data integrity, and constitutes an authorization bypass flaw (CWE‑639).
Affected Systems
This issue affects installations of Snipe‑IT produced by grokability:snipe‑it running any version older than 8.6.2. The patch that enforces asset‑level access checks is available in release 8.6.2 and later; the vulnerability is not listed in CISA’s KEV catalog.
Risk and Exploitability
The CVSS score of 5.0 indicates moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation at present. The vulnerability is not yet in the KEV catalog. Exploitation requires an authenticated user with reports.view who knows or can guess the global identifier of a pending acceptance belonging to another company. Because the endpoint accepts the identifier without verifying asset‑level ownership, the attack can be performed via normal web API or UI interaction—no additional privileges or advanced techniques are required beyond standard authentication.
OpenCVE Enrichment