Snipe-IT IDOR Vulnerability: How Your Assets Can Be Anyone’s Business!
Snipe-IT 8.0.4 has a sneaky flaw: an IDOR vulnerability allowing users to access other departments’ asset data just by tweaking a URL. It’s like window shopping for confidential info! Update to version 8.1.0 to shut this loophole and keep your asset secrets safe.

Hot Take:
Ah, the classic IDOR vulnerability strikes again! It’s like leaving the keys under the doormat for potential intruders, then wondering why they keep showing up for tea. Snipe-IT users, it’s time to update your software before your inventory data decides to go on a field trip without you!
Key Points:
- Snipe-IT versions up to 8.0.4 suffer from an IDOR vulnerability.
- Authenticated users can access restricted data by modifying the URL.
- The vulnerability affects asset assignment data across departments.
- Mitigation involves updating to version 8.1.0 or above.
- The vulnerability carries the CVE identifier CVE-2025-47226.
Already a member? Log in here