Impact
The vulnerability is an authorization bypass in the location print endpoints of Snipe‑IT. Authenticated attackers who have been granted only location view permission can call the printassigned and printallassigned endpoints. The system fails to enforce per‑model authorization checks, so the attacker can retrieve lists of users, assets, accessories, consumables and components for any location, even when the user does not normally have permission to view those specific models. This results in a confidentiality breach, exposing potentially sensitive information about company assets and personnel.
Affected Systems
The issue affects the asset‑management application Snipe‑IT developed by Grokability, specifically all released versions before 8.7.0 (including 8.6.3). The web application operates as a PHP/ Laravel service hosted on commonly supported OS platforms. Users of earlier versions must review their installation to determine whether the printassigned or printallassigned endpoints are exposed to their role set.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Because the flaw is reachable only by users who have authenticated to the system, it requires a legitimate account but does not allow arbitrary code execution. No known exploits appear in CISA KEV, and the EPSS score is not available, so while exploitation is possible, there is no evidence of active attacks. Nevertheless, the ability to read all model data for a location from a user with minimal permissions creates a useful information‑gathering vector that could be combined with other vulnerabilities or social engineering to advance an attacker’s objectives.
OpenCVE Enrichment