Description
Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authorization codes for bearer tokens inheriting full admin API permissions lasting up to 40 years.
Published: 2026-09-09
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

Snipe‑IT versions before 8.7.0 allow any authenticated user to create OAuth clients with arbitrary redirect URIs. An attacker can coerce an administrator into approving a consent screen for such a client, then trade the resulting authorization code for a bearer token that carries full administrative API privileges for up to forty years. The vulnerability is a classic authorization bypass that grants an attacker persistent, system‑wide access equivalent to that of a legitimate administrator.

Affected Systems

The affected vendor is Snipe‑IT, a popular asset‑management application. All releases prior to version 8.7.0 of the Snipe‑IT application are impacted; no specific sub‑version range is listed beyond the overall 8.7.0 cutoff.

Risk and Exploitability

The CVSS score of 8.5 reflects high severity, and while the EPSS score is not available, the absence of a KEV listing does not reduce the practical risk. Because the flaw is accessed via authenticated web requests, a low or medium‑skill attacker who has legitimate credentials can exploit it, potentially after social engineering or phishing to obtain such credentials. Once exploited, the attacker receives long‑lived admin API tokens, enabling complete control of the system.

Generated by OpenCVE AI on September 9, 2026 at 15:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later.
  • Restrict access to OAuth client management routes so that only trusted administrative accounts can create clients, using application‑level access controls or an external firewall rule.
  • Revoke any existing OAuth client registrations that were created by non‑admin users and invalidate or rotate any long‑lived tokens that may have been compromised.

Generated by OpenCVE AI on September 9, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authorization codes for bearer tokens inheriting full admin API permissions lasting up to 40 years.
Title Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:32.970Z

Reserved: 2026-09-08T11:32:11.096Z

Link: CVE-2026-86754

cve-icon Vulnrichment

Updated: 2026-09-20T00:31:15.331Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:24.590

Modified: 2026-09-20T01:16:30.750

Link: CVE-2026-86754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:00:14Z

Weaknesses