snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass instance-level restrictions and modify or disable accounts they should not access.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 12:17
Updated : 2026-09-14 20:16
NVD link : CVE-2026-85617
Mitre link : CVE-2026-85617
CVE.ORG link : CVE-2026-85617
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
