Impact
Snipe‑IT versions before 8.7.0 allow any authenticated user to create OAuth clients with arbitrary redirect URIs. An attacker can coerce an administrator into approving a consent screen for such a client, then trade the resulting authorization code for a bearer token that carries full administrative API privileges for up to forty years. The vulnerability is a classic authorization bypass that grants an attacker persistent, system‑wide access equivalent to that of a legitimate administrator.
Affected Systems
The affected vendor is Snipe‑IT, a popular asset‑management application. All releases prior to version 8.7.0 of the Snipe‑IT application are impacted; no specific sub‑version range is listed beyond the overall 8.7.0 cutoff.
Risk and Exploitability
The CVSS score of 8.5 reflects high severity, and while the EPSS score is not available, the absence of a KEV listing does not reduce the practical risk. Because the flaw is accessed via authenticated web requests, a low or medium‑skill attacker who has legitimate credentials can exploit it, potentially after social engineering or phishing to obtain such credentials. Once exploited, the attacker receives long‑lived admin API tokens, enabling complete control of the system.
OpenCVE Enrichment