Impact
Snipe‑IT versions earlier than 8.7.0 allow a bypass of authorization controls in the asset audit endpoints. The application incorrectly relies on query‑layer filtering instead of policy‑layer checks, so an authenticated user who has the assets.audit permission can write audit log entries for assets belonging to other company instances. This flaw falls under CWE‑863, exposing the audit trail to tampering and potentially masking unauthorized activity. The primary impact is the integrity erosion of audit logs and the confidentiality of the audit data.
Affected Systems
The vulnerability affects all deployments of the Snipe‑IT asset tracking system provided by grokability that run any version prior to 8.7.0. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA's KEV catalog, suggesting no confirmed public exploitation at this time. The likely attack vector is an authenticated request to the asset audit endpoint, requiring an active session with assets.audit permissions. If an attacker has those prerequisites, they can insert fabricated audit entries for assets outside their own scope. Because the flaw depends on internal permissions, the attack surface is limited to systems where privileged users exist, but the damage can cross organizational boundaries within a shared instance.
OpenCVE Enrichment