ZeroHour

CVE-2026-85617

niche

Authorization Bypass in Snipe-IT Bulk Delete Allows Out-of-Scope User Soft-Deletion

CVSS 4.0
8.7 high
EPSS
<1%p18
Published
()
Modified
AI analysis

Snipe-IT, a self-hosted open-source IT asset management platform, contains an authorization bypass (CWE-639) in its bulk user delete functionality in all versions prior to 8.6.3. An authenticated user with restricted, scope-limited permissions can submit a bulk delete request that includes user IDs outside their authorized scope, and the application soft-deletes them without validating that the target users belong to the attacker's permitted scope. This lets a low-privileged attacker modify or disable (soft-delete) accounts they should not be able to access, bypassing instance-level restrictions and potentially disrupting administrator or other users' accounts (CVSS 4.0: 8.7 High, network vector, low privileges, no user interaction). All Snipe-IT deployments running a version before 8.6.3 that use restricted user roles are affected. There is currently no public proof of concept, the flaw is not in the CISA KEV catalog, and EPSS is low (0.3%), indicating no known exploitation to date.

What to do: Upgrade to Snipe-IT 8.6.3 or later, which enforces scope checks in bulk delete. Until patched, restrict bulk-delete capability to fully privileged roles and review audit logs for bulk user delete actions performed by restricted users; check for and restore any accounts soft-deleted or modified outside their assigned company/scope.

Affected
Snipe-IT (open-source project) Snipe-IT IT asset managementall versions before 8.6.3
Estimated exposure
nichelikely tens of thousands of self-hosted instances at most (install base unpublished) — Snipe-IT is a self-hosted open-source asset-management tool typically deployed as a single internal instance per IT organization with relatively few users each, and no published install counts or internet-exposure scan data exist, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass instance-level restrictions and modify or disable accounts they should not access.

Weakness
CWE-639
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.