CVE-2026-84206
Received Received - Intake

Snipe-IT Bulk Asset Restore Permission Bypass

Vulnerability report for CVE-2026-84206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: VulnCheck

Description

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)
grokability snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Snipe-IT before version 8.7.0 has a permission issue in the bulk asset restore feature. The endpoint checks for the assets.edit permission instead of the required assets.delete permission. This allows users with edit rights to restore soft-deleted assets, bypassing intended permission separation and potentially undoing administrator deletions.

Detection Guidance

Check Snipe-IT logs for bulk restore operations by users with edit permissions. Look for POST requests to the bulk restore endpoint (/api/v1/hardware/bulk/restore) with asset identifiers. Review permission assignments to ensure users with edit rights do not have unintended access to restore functions.

Impact Analysis

Attackers with edit permissions could restore previously deleted assets, potentially regaining access to sensitive or unauthorized resources. This could lead to data leaks, unauthorized asset usage, or disruption of intended asset management controls.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and audit trails for data deletion and restoration. It may lead to unauthorized data recovery, compromising data integrity and confidentiality under standards like GDPR or HIPAA.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later to fix the permission gate issue. Temporarily restrict bulk restore functionality by removing edit permissions for users who do not require it. Audit user permissions to ensure proper separation between edit and delete rights.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84206. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart