Executive brief
A vulnerability in Snipe-IT, a popular open-source IT asset management system, allows users with limited permissions to lock administrators out of the system. By exploiting a flaw in the bulk-editing feature, a low-privileged user can deactivate administrator accounts and prevent them from resetting their passwords. This can lead to a total loss of administrative access and significant disruption to IT operations.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Snipe-IT's bulk user editing functionality. Users granted the granular 'users.edit' permission can modify the 'activated' and 'ldap_import' flags for any user, including administrators. By deactivating the 'activated' flag, an attacker can prevent login, and by modifying the 'ldap_import' flag, they can disable the ability to request password resets. This allows a low-privileged authenticated attacker to achieve a denial-of-service condition against administrative accounts. The issue is fixed in version 8.6.0.
Affected products
- Grokability Snipe-IT < 8.6.0
Timeline
- 2026-05-27: disclosed
- 2026-06-08: advisory: NVD published date
- 2026-06-23: patched: GitHub Advisory reviewed and updated
References
- https://api.github.com/users/louissanchez-vokecyber
- https://github.com/louissanchez-vokecyber
- https://api.github.com/users/louissanchez-vokecyber/gists%7B/gist_id%7D
- https://api.github.com/users/louissanchez-vokecyber/repos
- https://avatars.githubusercontent.com/u/20933064?v=4
- https://api.github.com/users/louissanchez-vokecyber/events%7B/privacy%7D