


Perceptive Security
SOC/SIEM Consultancy

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An a…
Published:
5 maart 2026 om 23:00:00
Alert date:
6 maart 2026 om 18:01:51
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access
Snipe-IT versions prior to 8.3.7 contain a mass assignment vulnerability that allows authenticated low-privileged users to modify restricted user account fields via malicious API requests. Attackers can target the Super Admin account by changing its email address and triggering a password reset, leading to complete administrative takeover of the Snipe-IT instance. This vulnerability affects sensitive user attributes related to account privileges that lack proper protection.
Technical details
Mitigation steps:
Affected products:
Snipe-IT
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-15602
https://github.com/grokability/snipe-it/releases/tag/v8.3.7
https://snipeitapp.com/
https://www.vulncheck.com/advisories/snipe-it-mass-assignment-vulnerability-leading-to-privilege-escalation
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
