Impact
Snipe‑IT allows any authenticated user with a valid web session and CSRF token to POST to /oauth/personal‑access‑tokens and generate a long‑lived bearer token for their own account. The generated token still respects existing endpoint authorization policies, so it does not provide additional privileges beyond those already held by the user. However, because the route is protected only by web and auth:web middleware, the administrative control that normally blocks API/scripted access via the self.api permission is defeated. The vulnerability is an authorization bypass (CWE‑863).
Affected Systems
The affected product is Snipe‑IT, versions 4.2.0 through 8.6.3. The issue resides in the Laravel Passport integration that automatically registers personal‑access‑token routes without the self.api permission gate. No other vendors or products are impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. EPSS is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector requires the attacker to possess a legitimate web session and the corresponding CSRF token, which can be obtained by social engineering or credential compromise. Upon success, the attacker can obtain a bearer token that gives them the same API access level as the user, thereby circumventing the administrator‑denied self.api permission. The attack does not grant higher privileges, but it removes useful administrative controls.
OpenCVE Enrichment