Executive brief
Snipe-IT is an open-source asset management system used by organizations to track hardware, software, and inventory. A flaw in the user edit feature allows employees with basic user-edit permissions to disable admin accounts, locking them out of the system until another administrator re-enables them. This can disrupt operations and lock legitimate administrators out of critical business systems.
Technical details
This is an authorization bypass vulnerability (CWE-269) in the UsersController::update() method. The vulnerable code assigns the activated field from the request payload before evaluating the canEditAuthFields authorization gate; when authorization fails, the pre-gated assignment persists and is saved to the database. An authenticated attacker holding the users.edit permission can craft a PUT request to /users/{id} with activated=0 to deactivate any user, including admin and superuser accounts. The vulnerability requires authentication and the users.edit permission scoped to the target's company, but affects only the activated field; sensitive fields (username, email, password, permissions) remain protected by the authorization gate, and the API and bulk-edit paths are unaffected. The patch (v8.7.0) moves all activated field assignments inside the authorization gate.
Affected products
- Snipe-IT Snipe-IT 8.2.0 through 8.6.x (fixed in 8.7.0)
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fix released in version 8.7.0