CVE-2025-15602

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

History

17 Apr 2026, 21:30

Type Values Removed Values Added
CPE cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
First Time Snipeitapp snipe-it
Snipeitapp
Summary
  • (es) Las versiones de Snipe-IT anteriores a la 8.3.7 contienen atributos de usuario sensibles relacionados con los privilegios de la cuenta que están insuficientemente protegidos contra la asignación masiva. Un usuario autenticado y con pocos privilegios puede elaborar una solicitud de API maliciosa para modificar campos restringidos de otra cuenta de usuario, incluida la cuenta de Super Administrador. Al cambiar la dirección de correo electrónico del Super Administrador y activar un restablecimiento de contraseña, un atacante puede tomar el control total de la cuenta de Super Administrador, lo que resulta en un control administrativo completo de la instancia de Snipe-IT.
References () https://github.com/grokability/snipe-it/releases/tag/v8.3.7 - () https://github.com/grokability/snipe-it/releases/tag/v8.3.7 - Product, Release Notes
References () https://snipeitapp.com/ - () https://snipeitapp.com/ - Product
References () https://www.vulncheck.com/advisories/snipe-it-mass-assignment-vulnerability-leading-to-privilege-escalation - () https://www.vulncheck.com/advisories/snipe-it-mass-assignment-vulnerability-leading-to-privilege-escalation - Patch, Third Party Advisory

06 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 17:16

Updated : 2026-04-17 21:30


NVD link : CVE-2025-15602

Mitre link : CVE-2025-15602

CVE.ORG link : CVE-2025-15602


JSON object : View

Products Affected

snipeitapp

  • snipe-it
CWE
CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes