← back
CVE-2025-47226mediumCWE-425

CVE-2025-47226

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 5epss 1.2%
from disclosure to weapon1 days
Published on NVDMay 2
1st PoC+1d
exploitation probability
1.2%top 33% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short

Snipe-IT versions before 8.1.0 allow unauthorized users to view asset information they shouldn't have access to. This is a permission flaw that could expose sensitive inventory details.

Technical detail

CWE-425 (Direct Request) authorization bypass in Snipe-IT <8.1.0 permits unauthenticated or low-privileged users to access asset data via direct API or endpoint requests. The vulnerability stems from insufficient access control checks on asset information endpoints, potentially exposing confidential inventory records without proper role-based restrictions.

Summary generated and translated by AI from the official description.
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected products
snipeitapp · Snipe-IT
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.