Executive brief
Snipe-IT is an open-source asset management system used to track IT equipment and licenses across organizations. A flaw in the bulk asset restore feature incorrectly checks user permissions, allowing employees with asset editing rights to undo administrator deletions and restore assets they should not have access to, potentially circumventing intended access controls.
Technical details
The vulnerability is an authorization bypass in the bulk asset restore endpoint. The endpoint gates access using the assets.edit permission instead of the intended assets.delete permission, allowing users with edit-only rights to post asset identifiers and restore soft-deleted assets. This violates permission separation logic, as asset deletion and restoration should be restricted to administrators or users with explicit delete permissions. The flaw affects Snipe-IT versions before 8.7.0. No known public exploitation has been reported, and patches are available in version 8.7.0 and later.
Affected products
- Snipe-IT Snipe-IT before 8.7.0
Timeline
- 2026-09-01: disclosed: Vulnerability details published on NVD
- 2026-08-19: patched: Fix available in Snipe-IT version 8.7.0 and later