Description
Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token endpoints (/account/api and /api/v1/account/personal-access-tokens). Any user with a valid web session and the corresponding CSRF token can POST to /oauth/personal-access-tokens and mint a long-lived bearer token for their own account, even when an administrator has denied the self.api permission. The issued token is still subject to existing per-endpoint authorization policies, so this is not a privilege escalation; it defeats the administrative control intended to block API/scripted access at the user's own permission level. Fixed in 8.7.0 (commit 3f74b8c), which registers overriding routes wrapped in the can:self.api middleware.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Permission bypass via OAuth personal‑access‑token routes
Action: Apply Patch
AI Analysis

Impact

Snipe‑IT allows any authenticated user with a valid web session and CSRF token to POST to /oauth/personal‑access‑tokens and generate a long‑lived bearer token for their own account. The generated token still respects existing endpoint authorization policies, so it does not provide additional privileges beyond those already held by the user. However, because the route is protected only by web and auth:web middleware, the administrative control that normally blocks API/scripted access via the self.api permission is defeated. The vulnerability is an authorization bypass (CWE‑863).

Affected Systems

The affected product is Snipe‑IT, versions 4.2.0 through 8.6.3. The issue resides in the Laravel Passport integration that automatically registers personal‑access‑token routes without the self.api permission gate. No other vendors or products are impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk. EPSS is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector requires the attacker to possess a legitimate web session and the corresponding CSRF token, which can be obtained by social engineering or credential compromise. Upon success, the attacker can obtain a bearer token that gives them the same API access level as the user, thereby circumventing the administrator‑denied self.api permission. The attack does not grant higher privileges, but it removes useful administrative controls.

Generated by OpenCVE AI on September 9, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Snipe‑IT to version 8.7.0 or newer, which registers the affected routes wrapped in the can:self.api middleware.
  • If an update is not immediately feasible, restrict or remove the automatically registered Laravel Passport personal‑access‑token routes (/oauth/personal-access-tokens*) by editing the routing configuration or disabling the corresponding Passport service provider.
  • Ensure administrators review and enforce the self.api permission setting, and monitor for the creation of personal access tokens by users who should not have them.

Generated by OpenCVE AI on September 9, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token endpoints (/account/api and /api/v1/account/personal-access-tokens). Any user with a valid web session and the corresponding CSRF token can POST to /oauth/personal-access-tokens and mint a long-lived bearer token for their own account, even when an administrator has denied the self.api permission. The issued token is still subject to existing per-endpoint authorization policies, so this is not a privilege escalation; it defeats the administrative control intended to block API/scripted access at the user's own permission level. Fixed in 8.7.0 (commit 3f74b8c), which registers overriding routes wrapped in the can:self.api middleware.
Title Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:26:06.374Z

Reserved: 2026-09-08T11:32:11.096Z

Link: CVE-2026-86755

cve-icon Vulnrichment

Updated: 2026-09-14T13:26:00.577Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:24.737

Modified: 2026-09-16T20:24:41.170

Link: CVE-2026-86755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:00:14Z

Weaknesses