CVE-2026-86760
Undergoing Analysis Undergoing Analysis - In Progress

Incorrect Authorization in Snipe-IT Allows User Activation Bypass

Vulnerability report for CVE-2026-86760, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating the canEditAuthFields authorization gate, so an authenticated non-admin user holding the users.edit permission in the target's company scope can submit a full valid PUT request to /users/{id} and toggle the activated flag on any user, including admin and superuser accounts. Deactivating an admin locks that account out of the application until another admin or superuser re-enables it. Only the activated field is affected; username, email, password and permissions remain protected by the gate, no data is disclosed, and the API (Api\UsersController::update) and bulk-edit paths are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
snipeit snipeit From 8.2.0 (inc) to 8.6.x|end_including=8.7.0 (inc)
grokability snipe-it From 8.2.0 (inc) to 8.6.x (inc)
grokability snipe-it 8.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86760 is an incorrect authorization flaw in Snipe-IT versions 8.2.0 through 8.6.x. It allows authenticated non-admin users with the users.edit permission to deactivate any user account, including admin and superuser accounts, by sending a PUT request to /users/{id}. The activated field is set before the authorization gate checks permissions, enabling unauthorized account deactivation.

The vulnerability only affects the activated field; other sensitive fields like username, email, password, and permissions remain protected. The issue was fixed in version 8.7.0 by moving the activated field assignment inside the authorization gate.

Detection Guidance

Check Snipe-IT version with: grep -r "version" config/app.php. If version is between 8.2.0 and 8.6.x, the system is vulnerable. Monitor logs for PUT requests to /users/{id} with activated=0 from non-admin users.

Impact Analysis

This vulnerability allows an attacker to deactivate admin accounts, locking them out of the application until another admin re-enables them. This can disrupt operations, prevent access to critical functions, and require administrative intervention to restore access.

The impact is limited to account deactivation; no data disclosure or permission escalation occurs. However, denial of access to admin accounts can lead to operational disruptions and increased administrative workload.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized deactivation of admin accounts, potentially violating access control requirements in GDPR (Article 32) and HIPAA (Security Rule). Unauthorized account deactivation may lead to unauthorized access or denial of service, affecting data integrity and availability.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. As a temporary workaround, revoke users.edit permissions from non-admin users or block PUT requests to /users/{id} from non-admin sessions until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86760. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart