Incorrect Authorization Affecting snipe/snipe-it package, versions >=8.2.0, <8.7.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.38% (30th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-SNIPESNIPEIT-20079201
  • published24 Sept 2026
  • disclosed9 Sept 2026
  • creditUnknown

Introduced: 9 Sep 2026

NewCVE-2026-86760  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade snipe/snipe-it to version 8.7.0 or higher.

Overview

snipe/snipe-it is an asset management system built on Laravel.

Affected versions of this package are vulnerable to Incorrect Authorization in the update process of the UsersController due to assigning the activated field from the request payload before evaluating the authorization gate. An attacker can disable or enable user accounts, including admin and superuser accounts, by submitting a valid PUT request to /users/{id} if they possess the users.edit permission in the target's company scope. This can result in locking out privileged users from the application until re-enabled by another admin or superuser. Only the activated field is affected; other sensitive fields remain protected. The API and bulk-edit paths are not impacted.

CVSS Base Scores

version 4.0
version 3.1