Impact
Snipe-IT versions before 8.7.0 contain a broken access control flaw in AssetModelPolicy where the files() method incorrectly inherits permission from assets.files. As a result, authenticated users who have only assets.files permission can upload and delete file attachments on Asset Model records, bypassing the intended models.files permission that should protect the shared Asset Model catalog. This flaw allows manipulation of shared model file attachments across company boundaries and can lead to data corruption or unintended data exposure.
Affected Systems
The vulnerability affects Snipe‑IT applications deployed by grokability. All installations of Snipe‑IT older than version 8.7.0 are susceptible; newer releases incorporate the corrected permission logic.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium‑level severity. EPSS information is unavailable, and the vulnerability is not listed in CISA KEV. An attacker only needs to be authenticated and granted assets.files permission, which is often a broader role, to exploit the flaw. The attack requires no special network exposure or additional privileges, making exploitation plausible in environments where assets.files is widely assigned.
OpenCVE Enrichment