CVE-2025-15602Disclosure(snipeitapp / snipe-it)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch snipeitapp snipe-it systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • snipe-it

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-06); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
snipe-it

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 2Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 103-0603-07
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure1Patch1
2026-03-072
Disclosure1General1
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-15602 - High Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged us... https://www.thehackerwire.com/vulnerability/CVE-2025-15602/ https://t.co/rL2gDo24LV

    Post summary

    Tweet announces CVE-2025-15602 in Snipe‑IT, detailing a high‑severity mass‑assignment flaw exposing sensitive user attributes.

    00010171
    128 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-15602: HIGH] Security alert: Snipe-IT versions < 8.3.7 vulnerable to unauthorized user privilege escalation via API. Update to latest version to secure your system.#cve,CVE-2025-15602,#cybersecurity https://cvefind.com/CVE-2025-15602

    Post summary

    The post alerts users to a high‑severity privilege escalation flaw in Snipe‑IT versions below 8.3.7 and urges an immediate upgrade to the latest release.

    1000091
    597 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2025-15602 - Grokability, Inc. - Snipe-IT - https://www.redpacketsecurity.com/cve-alert-cve-2025-15602-grokability-inc-snipe-it/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-15602 #grokability-inc #snipe-it

    Post summary

    The post announces a CVE alert for CVE-2025-15602 concerning Grokability Inc. and Snipe‑IT but offers no technical details, PoC, or actionable information.

    00000229
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15602 Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authent… https://www.cve.org/CVERecord?id=CVE-2025-15602

    Post summary

    The post announces CVE‑2025‑15602, a mass-assignment flaw in Snipe‑IT versions before 8.3.7 that exposes sensitive user privilege data, with no details on exploitation or remediation.

    00000120
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsnipeitappsnipe-it---

Explore more