Impact
Snipe‑IT versions below 8.7.0 allow an authenticated user who has only the kits.edit permission to attach a License, Consumable, Accessory, or Asset Model to a Predefined Kit through the updateLicense, updateConsumable, updateAccessory, updateModel, or storeModel endpoints. The application performs authorization only on the parent kit, not on the child object; consequently, the attachment succeeds even though the user would normally receive a 403 error when trying to read the object directly. After attachment, the kit relation index endpoint reveals the name of the attached object, providing a covert channel of disclosure. The vulnerability is an instance of object‑level authorization failure (CWE-863).
Affected Systems
Customers running Snipe‑IT version 8.6.3 or earlier are affected. The issue is fixed from version 8.7.0 onwards.
Risk and Exploitability
The CVSS score is 5.3, a medium severity that permits privilege escalation within a trusted realm of users. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attacking this flaw requires an authenticated session with kits.edit permission; an attacker could over‑attach privileged objects and gain indirect access to confidential names via the kit index.
OpenCVE Enrichment