Description
Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.
Published: 2026-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of product license keys
Action: Apply patch
AI Analysis

Impact

Snipe‑IT before version 8.7.0 does not correctly enforce the viewKeys permission during CSV export and API index operations. An authenticated user who only has licenses.view authority can retrieve all product license keys, effectively bypassing the intended access control. This flaw is classified as CWE‑204, reflecting a failure to properly secure the API and export functionality. The result is unintended disclosure of sensitive license data to users who do not have full read access.

Affected Systems

The vulnerability affects Snipe‑IT software from grokability. All installations running any Snipe‑IT build earlier than 8.7.0 are potentially impacted. No granular version list is provided beyond the stated cutoff, so any deployment dated before 8.7.0 requires attention.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium level of severity. No EPSS data is available, and the issue is not listed in CISA’s KEV catalog. Because the flaw requires authentication with licenses.view permission—a role likely assigned to users who manage licenses—an attacker would need to be a legitimate user or obtain credentials. Once authenticated, the attacker can issue a CSV export or API request and acquire all product keys in bulk. Thus, the exploitability is moderate; the impact is mainly confidentiality loss of license information.

Generated by OpenCVE AI on September 9, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or newer where the viewKeys gate is correctly enforced.
  • Limit the licenses.view permission to only those users who genuinely need it and ensure that viewKeys is also assigned to them.
  • Disable or restrict CSV export capabilities for users without viewKeys authority until a patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.
Title Snipe-IT before 8.7.0 License Key Exposure via CSV Export
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-204
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:29:41.300Z

Reserved: 2026-09-08T11:33:02.641Z

Link: CVE-2026-86758

cve-icon Vulnrichment

Updated: 2026-09-09T14:29:37.583Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:25.430

Modified: 2026-09-16T20:26:12.513

Link: CVE-2026-86758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:00:04Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy