Impact
Snipe-IT versions prior to 8.7.0 allow an authenticated user with the reports.view permission to issue asset acceptance report queries that are not properly confined to their own company. The flaw enables the user to view unaccepted asset lists and export them as CSV, revealing inventory details and assignee identities across all companies. This results in cross-company data disclosure and is an authorization bypass vulnerability.
Affected Systems
Vendor: grokability. Product: snipe-it. Affected versions: any build before 8.7.0. The issue affects all deployments that have not been upgraded to 8.7.0 or later.
Risk and Exploitability
CVSS score 5.3 indicates moderate severity. The EPSS score is not published, and the vulnerability is not listed in CISA KEV. Attackers must be authenticated with reports.view rights, which may be common in many Snipe-IT installations. Once authenticated, they can trigger the unaccepted_assets report or download its CSV export, yielding the sensitive cross-company data. The limited scope of the flaw reduces the attack surface, but the lack of an per-row access check means that any user with the role can access all pending acceptances. The modest CVSS and absent EPSS suggest that while it is exploitable, the risk is moderate and unlikely to attract widespread automated tools.
OpenCVE Enrichment