Impact
Snipe‑IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users with edit rights to restore soft‑deleted assets. The flaw is an access‑control issue (CWE‑863) that undermines data integrity, audit trails, and effectively grants privilege escalation for users who do not have delete permissions.
Affected Systems
All releases of the Snipe‑IT web application prior to version 8.7.0, as implemented by grokability. The vulnerability resides in the BulkAssetsController and affects any deployment using an 8.6.x (or earlier) build.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate risk. No EPSS value is provided, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a web request to the bulk restore API that requires an authenticated session with assets.edit permission; an attacker can supply asset identifiers and reverse administrator deletions, bypassing intended permission separation.
OpenCVE Enrichment