Impact
Snipe-IT before version 8.7.0 fails to enforce authorization within Livewire component lifecycle methods, allowing any authenticated user to replay signed snapshots via POST /livewire/update. This bypass lets attackers invoke protected methods that create OAuth clients, issue personal access tokens, and view sensitive administrative information, effectively escalating their privileges on the platform.
Affected Systems
The vulnerability affects the Snipe-IT asset management application produced by grokability (Snipe-IT), specifically all releases earlier than 8.7.0. No further sub‑version detail is specified.
Risk and Exploitability
The CVSS score of 7.4 indicates a moderate to high severity. Exploitation requires a valid authenticated session, but once authenticated attackers can perform privileged actions with no additional network reconnaissance. Because the EPSS score is not available and the issue is not listed in CISA’s KEV catalog, it is unclear how frequently the vulnerability is actively exploited. Nevertheless, the capability to create OAuth clients and tokens can compromise application integrity and data confidentiality if leveraged by an attacker.
OpenCVE Enrichment