CVE-2025-15602

HIGH

Snipe-IT <8.3.7 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-15602. PoCs published by Nxvh1337.

AI-analyzed exploit summary This repository contains functional exploit code for CVE-2025-15602, a mass assignment vulnerability in Snipe-IT. The exploit allows an authenticated attacker with user edit rights to take over a superadmin account by modifying the admin's email address.

Description

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super Admin account. By changing the email address of the Super Admin and triggering a password reset, an attacker can fully take over the Super Admin account, resulting in complete administrative control of the Snipe-IT instance.

Exploits (1)

nomisec WORKING POC
by Nxvh1337 · poc
https://github.com/Nxvh1337/CVE-2025-15602-PoC

This repository contains functional exploit code for CVE-2025-15602, a mass assignment vulnerability in Snipe-IT. The exploit allows an authenticated attacker with user edit rights to take over a superadmin account by modifying the admin's email address.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Snipe-IT
Auth required
Prerequisites: Authenticated user with edit rights · Target admin user ID, username, and first name
devstral-2 · analyzed Apr 17, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-915
Status published
Products (2)
snipe/snipe-it 0 - 8.3.7Packagist
snipeitapp/snipe-it < 8.3.7
Published Mar 06, 2026
Tracked Since Mar 07, 2026