Executive brief
Snipe-IT, a popular open-source asset management system, contains a security flaw in how it handles file uploads. An attacker could exploit this to upload and run malicious code on the server, potentially leading to a full system takeover and theft of sensitive asset data. This issue has been resolved in version 8.4.1.
Technical details
An insecure permissions vulnerability exists in Snipe-IT's UploadedFilesController.php. The API endpoint for uploading files (/api/v1/{object_type}/{id}/files) incorrectly validated user permissions using a 'view' check instead of an 'update' or 'write' check. This allowed users with basic read-only access to upload files. Because the application did not sufficiently restrict these uploads, it could be leveraged to achieve remote code execution (RCE). The vulnerability was addressed by updating the authorization logic to require 'update' permissions and was officially patched in version 8.4.1.
Affected products
- Grokability Snipe-IT <= 8.4.0
Timeline
- 2026-03-10: patched: Fix committed to repository
- 2026-05-05: advisory: Vendor advisory published via GitHub
- 2026-05-07: disclosed: CVE published to NVD