Description
snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of asset barcodes and tags across tenants
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the GET /hardware/{asset}/barcode endpoint of snipe‑it, which does not enforce asset view authorization. Authenticated users can supply arbitrary asset identifiers and retrieve barcode images, allowing them to enumerate asset tags and other metadata. The flaw is a missing authorization check (CWE-862) and leads to unauthorized data exposure of asset information, including soft‑deleted and cross‑company assets.

Affected Systems

Affected at the vendor level is snipe‑it from grokability. Any deployment of snipe‑it before version 8.7.0 is vulnerable, regardless of installation size or environment. The specific affected versions are all releases earlier than 8.7.0; the issue is present in each of these releases.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need to be authenticated to use the endpoint, but they can easily iterate asset IDs, making enumeration straightforward once credentials exist. While the vulnerability does not facilitate remote code execution, it permits cross‑tenant data exposure and inventory enumeration, which can aid further attacks.

Generated by OpenCVE AI on September 8, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update snipe‑it to version 8.7.0 or later, which restores proper authorization checks on the /hardware/{asset}/barcode endpoint.
  • If an upgrade cannot be applied immediately, restrict or disable access to the barcode endpoint for non‑privileged users, using application‑level access controls or network firewall rules.
  • Implement monitoring or rate‑limiting on asset ID requests to detect and mitigate enumeration attempts, and audit logs for any abnormal barcode retrieval activity.

Generated by OpenCVE AI on September 8, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.
Title snipe-it before 8.7.0 Missing Authorization via barcode endpoint
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-862
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T13:56:11.467Z

Reserved: 2026-09-08T11:31:09.014Z

Link: CVE-2026-86737

cve-icon Vulnrichment

Updated: 2026-09-10T13:56:05.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T16:18:36.830

Modified: 2026-09-10T14:17:10.093

Link: CVE-2026-86737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T17:15:17Z

Weaknesses