HIGH
Grokability, Inc.
CVE published 2026-03-06
CVE-2025-15602
CVE-2025-15602 is a mass assignment vulnerability in Snipe-IT versions prior to 8.3.7. This vulnerability allows an authenticated, low-privileged user to craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By exploiting this vulnerability, an attacker can potentially escalate privileges to gain complete administrative control of the Snipe-I [truncated]