Impact
Snipe‑IT is an IT asset and license management system that includes a UsersController::update action. The vendor’s code incorrectly processes requests that omit a permission field, allowing the request to overwrite a target user’s permission set with an incomplete, sparse result. The consequence is that an administrator or any user with users.edit privilege can remove administrative or other granular permissions from another account, effectively degrading the target’s role and compromising the integrity of the role hierarchy within the system.
Affected Systems
The vulnerability affects the Snipe‑IT application built by grokability. All installations running a version earlier than 8.6.0 are susceptible, while releases from 8.6.0 onward contain the fix.
Risk and Exploitability
A CVSS score of 7 classifies the issue as medium severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated with either administrative rights or users.edit permission and then invoke the UsersController::update endpoint to remove or reduce a target user’s privileges, potentially allowing further malicious activity or disrupting administrative control.
OpenCVE Enrichment