Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance. | |
| Title | Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation | |
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-06T16:16:08.531Z
Updated: 2026-03-06T22:51:14.910Z
Reserved: 2026-03-06T16:13:18.460Z
Link: CVE-2025-15602
No data.
Status : Received
Published: 2026-03-06T17:16:24.600
Modified: 2026-03-06T17:16:24.600
Link: CVE-2025-15602
No data.
ReportizFlow