Executive brief
Snipe-IT, a popular open-source asset management system, contains a security flaw that allows certain users to bypass two-factor authentication (2FA) protections. Specifically, a user with permissions to edit other profiles can reset the 2FA settings of a Superadmin. This could allow an attacker to weaken the security of the most powerful accounts in the system, potentially leading to full administrative takeover if they also possess the user's password.
Technical details
A missing authorization vulnerability (CWE-862) in Snipe-IT allows a user with the 'edit users' permission to reset the two-factor authentication (2FA) settings for Superadmin accounts. The root cause is an insufficient check on whether the actor has the authority to modify the security settings of a higher-privileged user. The attack requires low privileges and user interaction, and is restricted to the adjacent network according to the CVSS metrics. Successful exploitation allows an attacker to remove the 2FA requirement for a Superadmin, facilitating account takeover if credentials are known. This issue is resolved in version 8.5.0.
Affected products
- Grokability Snipe-IT < 8.5.0
Timeline
- 2026-06-08: disclosed
- 2026-06-08: patched: Fixed in version 8.5.0
- 2026-06-23: advisory