PT-2026-98144 · Snipe-It · Snipe-It
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.7.0
Description
An issue exists where the
CheckForTwoFactor middleware is enforced in the web middleware group but not in the API middleware group. This allows a user who has authenticated with a password but has not yet completed the second-factor authentication (2FA) challenge to access the personal-access-token API flow. By accessing the /two-factor endpoint, an attacker can obtain a snipeit passport token cookie and subsequently request a persistent API token via the /api/v1/account/personal-access-tokens endpoint, provided the account has the self.api permission.This persistent token grants full API access with the victim's permissions. If the victim is an administrator, the attacker can use the token to access the
users/two factor reset endpoint to clear the account's enrolled 2FA. This enables the attacker to enroll their own second factor, effectively taking over the administrator's web account and locking out the legitimate user.Recommendations
Update Snipe-IT to version 8.7.0.
As a temporary mitigation, restrict access to the
/api/v1/account/personal-access-tokens endpoint or disable the self.api permission for users until the update is applied.Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It