CVE-2025-47226: Medium severity snipe-it vulnerability
Published May 2, 2025
·Updated
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
Affected Software
3 affected componentsFixes available
Grokability Snipe-IT<8.1.0
Snipeitapp Snipe-it<8.1.0
composer/snipe/snipe-it<8.1.0
8.1.0
Remediation
Patch Available
Event History
May 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 PM
Data Sourced
via GitHub·09:30 PM
DescriptionSeverityWeaknessAffected Software
May 6, 2025
Exploit Published
12:00 AM
Known Exploited
10:04 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-47226?
CVE-2025-47226 has been categorized as a critical vulnerability due to incorrect authorization in Grokability Snipe-IT.
2
How do I fix CVE-2025-47226?
To remediate CVE-2025-47226, upgrade your Grokability Snipe-IT version to 8.1.0 or later.
3
What type of vulnerability is CVE-2025-47226?
CVE-2025-47226 is an authorization vulnerability that allows unauthorized access to asset information.
4
Which versions of Snipe-IT are affected by CVE-2025-47226?
Grokability Snipe-IT versions prior to 8.1.0 are affected by CVE-2025-47226.
5
Is there a workaround for CVE-2025-47226?
There are no official workarounds for CVE-2025-47226; the only solution is to upgrade to the patched version.