Description
snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries against cross-company assets if the query-layer scope were bypassed or refactored.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass enabling audit log tampering across organizations
Action: Apply patch
AI Analysis

Impact

Snipe‑IT versions earlier than 8.7.0 allow a bypass of authorization controls in the asset audit endpoints. The application incorrectly relies on query‑layer filtering instead of policy‑layer checks, so an authenticated user who has the assets.audit permission can write audit log entries for assets belonging to other company instances. This flaw falls under CWE‑863, exposing the audit trail to tampering and potentially masking unauthorized activity. The primary impact is the integrity erosion of audit logs and the confidentiality of the audit data.

Affected Systems

The vulnerability affects all deployments of the Snipe‑IT asset tracking system provided by grokability that run any version prior to 8.7.0. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA's KEV catalog, suggesting no confirmed public exploitation at this time. The likely attack vector is an authenticated request to the asset audit endpoint, requiring an active session with assets.audit permissions. If an attacker has those prerequisites, they can insert fabricated audit entries for assets outside their own scope. Because the flaw depends on internal permissions, the attack surface is limited to systems where privileged users exist, but the damage can cross organizational boundaries within a shared instance.

Generated by OpenCVE AI on September 9, 2026 at 15:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or newer.
  • If an upgrade is not possible, tightly restrict the assets.audit permission to trusted users only and monitor audit logs for anomalous entries.
  • Perform a manual audit of recent log entries to detect any tampering that may have already occurred.

Generated by OpenCVE AI on September 9, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries against cross-company assets if the query-layer scope were bypassed or refactored.
Title snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:38.119Z

Reserved: 2026-09-08T11:32:11.095Z

Link: CVE-2026-86752

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:40.887Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:24.307

Modified: 2026-09-14T20:27:46.977

Link: CVE-2026-86752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:45:05Z

Weaknesses