5.3
CVE-2026-84206
- EPSS 0.22%
- Veröffentlicht 01.09.2026 15:19:00
- Zuletzt bearbeitet 29.09.2026 19:00:51
- Erkennungen
Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore
Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Snipeitapp ≫ Snipe-it Version < 8.7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.126 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/grokability/snipe-it
https://github.com/grokability/snipe-it/security/advisories/GHSA-m863-2j99-jxwm
https://github.com/grokability/snipe-it/commit/686329001aa457f716b269600659839a58895fee
https://github.com/grokability/snipe-it/releases/tag/v8.7.0
https://github.com/grokability/snipe-it/blob/v8.6.3/app/Http/Controllers/Assets/BulkAssetsController.php
https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-authorization-bypass-via-bulk-restore