PT-2026-85513 · Snipe-It · Snipe-It

·

CVE-2026-85617

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions snipe-it versions prior to 8.6.3
Description An authorization bypass exists in the bulk delete functionality. This issue allows restricted users to perform a soft-delete on users outside their authorized scope by including unauthorized user IDs in bulk delete requests, enabling them to modify or disable accounts they are not permitted to access.
Recommendations Update snipe-it to version 8.6.3 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85617
GHSA-MX3G-8V84-J6GG

Affected Products

Snipe-It