Impact
Snipe-IT versions prior to 8.7.0 lack proper company‑scope filtering on the GET /hardware/requested endpoint when Full Multiple Company Support is enabled. The flaw allows users with the assets.view permission in an authenticated session to view pending asset requests from all companies, exposing the names of requested items, requester display names, profile links, locations, and expected check‑in dates. The vulnerability results in the disclosure of sensitive cross‑tenant data to any authenticated user possessing the view permission, representing an unauthorized information leakage.
Affected Systems
The affected product is Snipe‑IT, provided by grokability. Versions released before 8.7.0 are impacted, especially when the Full Multiple Company Support feature is active. Users running those versions should review their installation date and consult the vendor for a fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated access, as the flaw requires an authenticated user with assets.view permissions and does not involve parameter manipulation. If an attacker possesses legitimate credentials, they can retrieve cross‑tenant data via standard API calls, making remediation a priority for organizations with multi‑company deployments.
OpenCVE Enrichment