Impact
Snipe-IT versions before 8.7.0 record the ID of the target user in the checkout action instead of the ID of the authenticated caller. This improper ownership management causes all audit trail entries in the consumables_users table to be associated with the wrong user. The result is a loss of traceability for actions performed on consumables, which can enable malicious insiders or attackers to conceal their activity and undermine accountability mechanisms.
Affected Systems
The vulnerability applies to the Snipe-IT asset management application provided by grokability. All releases prior to version 8.7.0 are affected; no specific patch releases other than 8.7.0 or later are available. Any instance running an earlier version is susceptible if the consumables.checkout API is available.
Risk and Exploitability
The risk level is assessed as medium with a CVSS score of 5.3. Exploitation requires that the attacker be an authenticated user with the consumables.checkout permission, so remote unauthenticated attacks are not possible. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that while the likelihood of exploitation is uncertain, the potential impact on accountability could be significant. The primary attack path is a normal API call to the consumables checkout endpoint where the payload includes the user ID to be checked out.
OpenCVE Enrichment