Junglewise Threat Intelligence

CVE-2026-86760: Snipe-IT authorization bypass in user account activation toggle

CVE-2026-86760 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an open-source asset management system used by organizations to track hardware, software, and inventory. A flaw in the user edit feature allows employees with basic user-edit permissions to disable admin accounts, locking them out of the system until another administrator re-enables them. This can disrupt operations and lock legitimate administrators out of critical business systems.

Technical details

This is an authorization bypass vulnerability (CWE-269) in the UsersController::update() method. The vulnerable code assigns the activated field from the request payload before evaluating the canEditAuthFields authorization gate; when authorization fails, the pre-gated assignment persists and is saved to the database. An authenticated attacker holding the users.edit permission can craft a PUT request to /users/{id} with activated=0 to deactivate any user, including admin and superuser accounts. The vulnerability requires authentication and the users.edit permission scoped to the target's company, but affects only the activated field; sensitive fields (username, email, password, permissions) remain protected by the authorization gate, and the API and bulk-edit paths are unaffected. The patch (v8.7.0) moves all activated field assignments inside the authorization gate.

Affected products

  • Snipe-IT Snipe-IT 8.2.0 through 8.6.x (fixed in 8.7.0)

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fix released in version 8.7.0

References

Related threats