Description
Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can read plaintext encrypted custom field values by opening asset forms, bypassing the assets.view.encrypted_custom_fields permission check.
Published: 2026-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Update
AI Analysis

Impact

Snipe-IT prior to version 8.7.0 fails to enforce access controls for encrypted custom‑field values in asset form templates such as listbox, textarea, markdown‑textarea and date/datetime picker elements. Users who possess any of the assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can open asset forms and read the plaintext encrypted custom‑field data, bypassing the assets.view.encrypted_custom_fields check. This allows confidentiality compromise of sensitive asset information stored in custom fields.

Affected Systems

The vulnerability affects installations of Snipe‑IT by grokability, specifically all releases before 8.7.0. No individual patch level was specified, so any pre‑8.7.0 deployment is susceptible.

Risk and Exploitability

The CVSS score of 7.1 classifies this as a moderate‑severity vulnerability. EPSS data is not available and the issue is not listed in the CISA KEV catalog, indicating no publicly known widespread exploitation yet. The exploit requires legitimate authentication with one of the listed permissions, so the attack vector is authenticated; the threat is mainly internal or from a compromised user account. The risk is the accidental or intentional disclosure of confidential asset details to privileged but not explicitly authorized users.

Generated by OpenCVE AI on September 9, 2026 at 15:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later to enforce proper permission checks for encrypted custom fields.
  • If an immediate upgrade is not feasible, limit the assets.edit, assets.checkin, assets.checkout, and assets.audit permissions to only trusted administrators and consider revoking them from ordinary users.
  • Review the configuration of custom field encryption and ensure that only users with the assets.view.encrypted_custom_fields permission can access decrypted values.

Generated by OpenCVE AI on September 9, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can read plaintext encrypted custom field values by opening asset forms, bypassing the assets.view.encrypted_custom_fields permission check.
Title Snipe-IT before 8.7.0 Information Disclosure via Custom Fields
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-862
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:29.116Z

Reserved: 2026-09-08T11:32:11.096Z

Link: CVE-2026-86757

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:38.844Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:25.170

Modified: 2026-09-16T20:25:53.200

Link: CVE-2026-86757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:45:16Z

Weaknesses