Multiple Authorization Bypass Vulnerabilities in Snipe-IT 8.7.0

Multiple Authorization Bypass Vulnerabilities in Snipe-IT 8.7.0

First seen 10 Sep 2026, 00:44 UTC www.vulncheck.com 64.5

Article Content

Browse articles
ThreatCluster

Three critical authorization bypass vulnerabilities have been identified in Snipe-IT versions prior to 8.7.0. The vulnerabilities allow unauthorized access via OAuth clients, API user creation and updates, and asset history CSV imports. Organizations using affected versions are at risk of unauthorized data manipulation and access. The vulnerabilities have been reported by multiple sources on the same day, indicating a significant threat landscape. No specific CVEs have been assigned yet, but the vulnerabilities are severe enough to warrant immediate attention. Users are advised to upgrade to version 8.7.0 or later to mitigate these risks. The current status of exploitation in the wild is unknown, but the potential impact is substantial. Administrators should prioritize patching to prevent possible breaches.

Key Points: • Three critical authorization bypass vulnerabilities found in Snipe-IT before version 8.7.0. • Vulnerabilities allow unauthorized access through OAuth clients and API user updates. • Immediate upgrade to version 8.7.0 is recommended to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-10
Vulnerabilities disclosed
Multiple authorization bypass vulnerabilities reported for Snipe-IT versions before 8.7.0, affecting user access and data integrity.
VulnCheck
2026-09-10
Advisory issued
VulnCheck issued advisories for each of the three vulnerabilities, urging users to upgrade to version 8.7.0.
VulnCheck
2026-09-10
Risk assessment
Organizations using affected versions are assessed to be at high risk of unauthorized access and data manipulation.
VulnCheck