Executive brief
Snipe-IT is an asset management and licensing platform. A flaw in how it controls access to product license keys allows users with basic view permissions to download all license keys in bulk via CSV export or discover valid keys through API response patterns, even though only certain administrative roles should access this sensitive data. This could lead to unauthorized software activation or key reuse.
Technical details
The vulnerability is an authorization bypass in which two code paths fail to enforce the viewKeys permission gate when accessing the serial (product key) column. Vector A affects the CSV export endpoint (GET /licenses/export), which checks only the coarser view permission and streams raw serial values without masking. Vector B affects the API index endpoint (GET /api/v1/licenses), which allows filtering by product_key and searching on serial, leaking key existence through response count discrepancies (total=0 vs total>0) rather than showing the actual key value. Both vectors require authentication but only the licenses.view permission, not the restrictive viewKeys gate that the API transformer correctly applies elsewhere. Patches were released in version 8.7.0, which applies the same masking mask used in the transformer to the CSV export, suppresses the product_key filter for unprivileged users, and removes serial from searchable attributes in free-text search.
Affected products
- Snipe Snipe-IT before 8.7.0
Timeline
- 2026-09-09: disclosed: Public disclosure via NVD and GitHub Security Advisory
- 2026-08-24: patched: Fixed in version 8.7.0