Junglewise Threat Intelligence

CVE-2026-37709: Grokability Snipe-IT insecure permissions in UploadedFilesController

CVE-2026-37709 · Severity: critical · CVSS 9.8 · Published 2026-05-07

Technologies: Grokability Snipe-It, snipe/snipe-it (Packagist). Vendors: Snipeitapp, Packagist.

Executive brief

Snipe-IT, a popular open-source asset management system, contains a security flaw in how it handles file uploads. An attacker could exploit this to upload and run malicious code on the server, potentially leading to a full system takeover and theft of sensitive asset data. This issue has been resolved in version 8.4.1.

Technical details

An insecure permissions vulnerability exists in Snipe-IT's UploadedFilesController.php. The API endpoint for uploading files (/api/v1/{object_type}/{id}/files) incorrectly validated user permissions using a 'view' check instead of an 'update' or 'write' check. This allowed users with basic read-only access to upload files. Because the application did not sufficiently restrict these uploads, it could be leveraged to achieve remote code execution (RCE). The vulnerability was addressed by updating the authorization logic to require 'update' permissions and was officially patched in version 8.4.1.

Affected products

  • Grokability Snipe-IT <= 8.4.0

Timeline

  • 2026-03-10: patched: Fix committed to repository
  • 2026-05-05: advisory: Vendor advisory published via GitHub
  • 2026-05-07: disclosed: CVE published to NVD

References

Related threats