Impact
Snipe‑IT versions up to 8.6.3 contain a race condition that allows two concurrent checkout requests for the same asset to both pass the availability check and commit, resulting in duplicate checkout-history entries, a doubled checkout counter, and two checkout events for a single assignment. The visible asset assignment remains correct but the audit logs and utilization reports become unreliable, leading to inconsistent asset management data.
Affected Systems
The vendor is grokability, product Snipe‑IT. All releases prior to 8.7.0, including 8.6.3 and earlier, as well as pre‑release commits before the fix, are affected. System administrators should review whether their environment runs any of these versions.
Risk and Exploitability
The CVSS score is 2.1, indicating low overall severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session with the assets.checkout permission (or superuser rights) and precise concurrent timing; the likely attack vector is internal use or a privileged user executing simultaneous checkouts. Because the impact is limited to audit data integrity rather than direct control loss, the risk level remains low, but corrupted audit trails can impede forensic investigations and reporting.
OpenCVE Enrichment