Executive brief
Snipe-IT is asset inventory management software used by organizations to track hardware and licenses. When an administrator deactivates a user account to revoke access—such as when an employee leaves or credentials are compromised—the deactivation is enforced only on the web login portal. A deactivated user's existing API tokens continue to grant full read and write access to sensitive asset data until the token naturally expires. Additionally, deactivated users with administrative permissions can reactivate themselves through the API, permanently defeating the access control.
Technical details
The vulnerability is an authentication bypass caused by missing middleware validation on the API authentication path. The CheckUserIsActivated middleware exists in the web middleware group and correctly blocks deactivated users at login, but it is not applied to the api middleware group in app/Http/Kernel.php. Additionally, when a user is deactivated, the application does not revoke their Passport personal access tokens, allowing them to continue authenticating via API with their prior permission level. The attack vector is network-based; any attacker with a deactivated user's API token can invoke REST API endpoints (hardware, users, licenses, etc.) without any additional preconditions. A deactivated account holding user-management permissions can call the user update API to reactivate itself, permanently bypassing the deactivation control. The fix (version 8.7.0) adds CheckUserIsActivated to the api middleware group.
Affected products
- Grokability Snipe-IT before 8.7.0
Timeline
- 2026-08-24: disclosed
- 2026-09-09: advisory: NVD published
- 2026-07-25: patched: Fix committed to repository