PatchSiren cyber security CVE debrief
CVE-2025-15602 Grokability, Inc. CVE debrief
CVE-2025-15602 is a mass assignment vulnerability in Snipe-IT versions prior to 8.3.7. This vulnerability allows an authenticated, low-privileged user to craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By exploiting this vulnerability, an attacker can potentially escalate privileges to gain complete administrative control of the Snipe-IT instance. The vulnerability is particularly concerning because it can be exploited by changing the email address of the Super Admin and triggering a password reset. Defenders responsible for Snipe-IT instances, especially those with low-privileged users, should assess their Snipe
- Vendor
- Grokability, Inc.
- Product
- Snipe-IT
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-06
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-03-06
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Snipe-IT instances, particularly those with low-privileged users, should assess exposure and prioritize patching or compensating controls to prevent exploitation.
Why it matters
CVE-2025-15602 is a mass assignment vulnerability in Snipe-IT versions prior to 8.3.7, allowing for potential privilege escalation and increased risk of unauthorized access. Defenders should prioritize verifying exposure and applying the patch or compensating controls.
- Potential privilege escalation to complete administrative control of the Snipe-IT instance
- Increased risk of unauthorized access to sensitive user attributes
- Possible disruption of Snipe-IT services due to exploitation
- Need for verification of current Snipe-IT version and exposure
Technical summary
The mass assignment vulnerability in Snipe-IT versions prior to 8.3.7 allows an authenticated, low-privileged user to craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. This can be done by changing the email address of the Super Admin and triggering a password reset, potentially leading to complete administrative control of the Snipe-IT instance.
Defensive priority
Defenders should prioritize verifying exposure, assessing the current Snipe-IT version, and applying the patch (version 8.3.7) or other compensating controls to prevent exploitation.
Recommended defensive actions
- Verify the current Snipe-IT version and assess exposure to CVE-2025-15602
- Apply the patch (version 8.3.7) or other compensating controls to prevent exploitation
- Monitor for suspicious API requests that could indicate attempted exploitation
- Restrict access to sensitive user attributes to limit the potential impact
- Conduct a thorough review of user accounts and roles to identify and mitigate potential vulnerabilities
- Implement additional logging and monitoring to detect and respond to potential security incidents
- Coordinate with stakeholders to ensure awareness and preparedness for potential exploitation
Evidence notes
The CVE record and source item provide details on the mass assignment vulnerability in Snipe-IT versions prior to 8.3.7. The vendor, Grokability, Inc., has released a patch (version 8.3.7) to address this issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/15xxx/CVE-2025-15602.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/releases/tag/v8.3.7
Supplemental source - release-notes, patch
-
Source reference
Unverified legacy reference
URL: https://snipeitapp.com/
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/snipe-it-mass-assignment-vulnerability-leading-to-privilege-escalation
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.