Executive brief
Snipe-IT is an open-source asset management platform used by organizations to track IT equipment and inventory. A flaw in its OAuth token system allows any logged-in user to register unauthorized OAuth applications and trick administrators into granting access tokens with full administrative API permissions. An attacker could use these tokens to access sensitive data, modify records, or manage assets without authorization for up to 40 years.
Technical details
Snipe-IT before version 8.7.0 fails to properly restrict access to Laravel Passport's OAuth client management routes (/oauth/clients endpoints for GET, POST, PUT, DELETE operations). While Snipe-IT's own admin OAuth panel is gated to superusers, the underlying Passport routes are accessible to any authenticated user. An attacker with a valid session can POST to /oauth/clients to register a malicious OAuth client pointing to an attacker-controlled redirect URI. If the attacker then convinces an administrator to click a consent link and approve the client, the resulting authorization code is redirected to the attacker's server. The attacker can exchange this code for a bearer token inheriting the admin's full API permissions and valid for up to 40 years by default. The fix involves overriding the Passport routes in Snipe-IT's route configuration with superuser authorization checks, applied before Passport's service provider loads its own routes.
Affected products
- Snipe-IT Snipe-IT before 8.7.0
Timeline
- 2026-08-24: disclosed
- 2026-09-09: patched: Version 8.7.0 released