Authorization Flaw in Snipe-IT Versions Exposing User Account Management Risks
CVE-2026-86760
5.3MEDIUM
What is CVE-2026-86760?
Snipe-IT versions 8.2.0 through 8.6.x exhibit a significant authorization flaw within the user update functionality. This vulnerability enables authenticated non-admin users with the users.edit permission to toggle the activation status of any user, including administrators, leading to potential account lockout scenarios. Although username, email, and permissions remain secure, the flaw could allow unauthorized management of user status, posing risks to application access and security. The issue has been addressed in version 8.7.0.
Affected Version(s)
snipe-it 8.2.0 < 8.7.0
snipe-it 8.7.0
