Impact
Snipe-IT versions up to 8.6.3 contain a time‑of‑check to time‑of‑use flaw in the consumable checkout API. An authenticated user can send multiple concurrent checkout requests that all validate the available quantity before a database transaction locks the record. The transaction then creates checkout entries without re‑checking stock, allowing the remaining quantity to become negative. This flaw does not execute arbitrary code but corrupts inventory data, potentially causing financial loss or operational outages.
Affected Systems
All installations of Snipe‑IT v8.6.3 and earlier are vulnerable. The flaw applies to the consumable checkout endpoint POST /api/v1/consumables/{consumable_id}/checkout. The affected product is the Snipe‑IT asset tracking system maintained by grokability. Fixed in version 8.7.0 and later, which re‑locks the consumable row and re‑validates availability inside the transaction.
Risk and Exploitability
The severity score is 7.1, indicating a moderate to high risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet. Exploitation requires an authenticated user with permission to check out consumables. By submitting two or more concurrent requests for the same item, an attacker can force the stock count negative, creating obvious inventory discrepancies that may be hard to detect without audit processes. The attack path is straightforward and does not require specialized skills beyond sending rapid parallel HTTP requests.
OpenCVE Enrichment