CyberRota Analysis
AI-GeneratedSnipe-IT versions prior to 8.7.0 are vulnerable due to inadequate enforcement of checkout authorization, allowing authenticated users with edit permissions to bypass check-in procedures and modify custody records. This vulnerability can lead to unauthorized asset reassignments, potentially compromising asset management integrity. Organizations using affected versions should prioritize this issue, especially those with strict asset tracking and management requirements.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign assets, bypass check-in procedures, and alter custody records by submitting assigned_user, assigned_asset, or assigned_location parameters to PATCH /api/v1/hardware/{id}.