Executive brief
Snipe-IT is an open-source asset management system used by organizations to track and manage IT hardware inventory. A flaw in versions before 8.7.0 allows any logged-in user to reassign company assets and falsify audit logs without proper permission checks, potentially enabling unauthorized asset transfers and destruction of audit accountability across the entire system or across multiple companies in multi-tenant deployments.
Technical details
The POST /hardware/history endpoint (AssetsController::postImportHistory) lacks authorization checks despite being part of a legacy CSV import feature, allowing authenticated users to submit asset reassignment records without admin or asset-edit privileges. While the corresponding GET handler enforces admin authorization, the POST handler relies only on class-level auth middleware, permitting any authenticated session to submit a multipart CSV file. For each matched asset_tag, the importer reassigns assets and creates fake audit log entries attributed to the attacker, bypassing company scoping and normal checkout policies. In multi-company (FMCS) deployments this becomes a cross-tenant integrity issue. The vulnerability was fixed in version 8.7.0 by removing the legacy importer entirely and replacing it with a new Livewire-based importer that enforces proper authorization checks.
Affected products
- Snipe-IT Snipe-IT before 8.7.0
Timeline
- 2026-08-24: disclosed: GitHub Security Advisory GHSA-2232-926w-qvr9 published
- 2026-09-09: disclosed: CVE-2026-86759 published
- 2026-09-09: patched: Fixed in version 8.7.0