Description
Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the components.view check is applied only to the response's available_actions.view flag and not to the returned data. As a result, an authenticated user holding only assets.view can enumerate component IDs, names, assigned quantities, and notes that are otherwise protected — the direct GET /api/v1/components/<id> endpoint correctly returns 403 Forbidden for such users.
Published: 2026-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Exposure by Permission Bypass
Action: Immediate Patch
AI Analysis

Impact

Snipe-IT versions up to 8.6.4 fail to enforce the components.view permission when an authenticated user calls GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset and relies on a flag in the response to indicate component view rights, but it does not prevent the returned data from being displayed. Consequently, any user with only assets.view can enumerate component identifiers, names, quantities, and notes, data that would otherwise be protected. This flaw represents a permission bypass that leads to unauthorized disclosure of sensitive inventory information, classified as CWE-862.

Affected Systems

The vulnerability affects the Snipe-IT application, maintained by grokability, at version 8.6.4 and earlier. It was resolved in version 8.7.0. The affected component is the authenticated API endpoint GET /api/v1/hardware/<asset-id>/assigned/components.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity that can compromise confidentiality of component data. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, yet the flaw can be exploited by any authenticated user with assets.view permission. No additional vulnerabilities or prerequisites are required beyond owning an account with limited asset viewing rights, making the attack vector straightforward and potentially impactful to systems that rely on strict access controls.

Generated by OpenCVE AI on September 9, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe-IT to version 8.7.0 or later to apply the fix that enforces components.view on the endpoint.
  • Ensure that users who only require assets.view privilege do not have the components.view permission, thereby preventing unauthorized component enumeration.
  • Audit and review user permissions and recent component access logs to detect and revoke any misuse of the endpoint.

Generated by OpenCVE AI on September 9, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the components.view check is applied only to the response's available_actions.view flag and not to the returned data. As a result, an authenticated user holding only assets.view can enumerate component IDs, names, assigned quantities, and notes that are otherwise protected — the direct GET /api/v1/components/<id> endpoint correctly returns 403 Forbidden for such users.
Title Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-862
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:32.658Z

Reserved: 2026-09-08T11:33:02.641Z

Link: CVE-2026-86764

cve-icon Vulnrichment

Updated: 2026-09-20T00:31:10.679Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:26.597

Modified: 2026-09-20T01:16:31.023

Link: CVE-2026-86764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:30:09Z

Weaknesses