Impact
Snipe‑IT versions prior to 8.7.0 do not validate the requestable flag when processing POST requests to /account/request/asset_model/{modelId}. This allows an authenticated user to submit a checkout request for an asset model that has been marked as non-requestable, effectively bypassing the intended administrative restriction. The consequence is that assets can be removed from inventory without proper approval, which may lead to loss of asset control, billing inaccuracies, or unauthorized asset access.
Affected Systems
The affected software is Snipe‑IT produced by grokability. All releases before version 8.7.0 are vulnerable. No additional version qualifiers are provided.
Risk and Exploitability
The CVSS base score for this issue is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access to the system; a legitimate user account can target the endpoint directly. Once the bypass is achieved, the attacker can generate checkout requests for non-requestable assets and thereby compromise inventory integrity. Because only authenticated actors can exploit the flaw, the risk is contingent on internal threat models and the safeguarding of user credentials.
OpenCVE Enrichment