Description
Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only assets.files permission can mutate shared model file attachments across company boundaries and bypass the dedicated models.files permission intended to restrict file management on the shared Asset Model catalog.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Management
Action: Immediate Patch
AI Analysis

Impact

Snipe-IT versions before 8.7.0 contain a broken access control flaw in AssetModelPolicy where the files() method incorrectly inherits permission from assets.files. As a result, authenticated users who have only assets.files permission can upload and delete file attachments on Asset Model records, bypassing the intended models.files permission that should protect the shared Asset Model catalog. This flaw allows manipulation of shared model file attachments across company boundaries and can lead to data corruption or unintended data exposure.

Affected Systems

The vulnerability affects Snipe‑IT applications deployed by grokability. All installations of Snipe‑IT older than version 8.7.0 are susceptible; newer releases incorporate the corrected permission logic.

Risk and Exploitability

The CVSS score is 5.3, indicating a medium‑level severity. EPSS information is unavailable, and the vulnerability is not listed in CISA KEV. An attacker only needs to be authenticated and granted assets.files permission, which is often a broader role, to exploit the flaw. The attack requires no special network exposure or additional privileges, making exploitation plausible in environments where assets.files is widely assigned.

Generated by OpenCVE AI on September 9, 2026 at 15:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Snipe‑IT installation to version 8.7.0 or later to enforce correct access control on Asset Model file attachments.
  • If an immediate upgrade is not feasible, revoke or restrict the assets.files permission for users who should not manage model file attachments and disable file uploads for Asset Model records.
  • Continuously monitor application logs for unauthorized file upload or deletion activity and audit user actions related to Asset Model attachments.

Generated by OpenCVE AI on September 9, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only assets.files permission can mutate shared model file attachments across company boundaries and bypass the dedicated models.files permission intended to restrict file management on the shared Asset Model catalog.
Title Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-284
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:32.356Z

Reserved: 2026-09-08T11:35:02.617Z

Link: CVE-2026-86774

cve-icon Vulnrichment

Updated: 2026-09-20T00:31:06.551Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:28.363

Modified: 2026-09-20T01:16:31.293

Link: CVE-2026-86774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:15:06Z

Weaknesses