5.3

CVE-2026-84206

Exploit

Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Snipeitapp ≫ Snipe-it Version < 8.7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.126
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 5.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
disclosure@vulncheck.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/grokability/snipe-it
Product
https://github.com/grokability/snipe-it/security/advisories/GHSA-m863-2j99-jxwm
Patch
Vendor Advisory
Exploit
Mitigation
https://github.com/grokability/snipe-it/commit/686329001aa457f716b269600659839a58895fee
Patch
https://github.com/grokability/snipe-it/releases/tag/v8.7.0
Release Notes
https://github.com/grokability/snipe-it/blob/v8.6.3/app/Http/Controllers/Assets/BulkAssetsController.php
Product
https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-authorization-bypass-via-bulk-restore
Patch
Third Party Advisory
Exploit