THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vgx7-c78r-69w9 (high) — Snipe-IT has an authorization bypass on bulk editing users

[GHSA] GHSA-vgx7-c78r-69w9 (high) — Snipe-IT has an authorization bypass on bulk editing users

medgithub_advisoriesPublished 2026-08-28

GHSA-vgx7-c78r-69w9 Severity: high CVE: CVE-2026-55460

Snipe-IT has an authorization bypass on bulk editing users

### Impact An authenticated non-admin user with `users.view` and `users.edit`, but without `users.delete`, can directly POST to `/users/bulksave` and soft-delete another non-admin user. The UI and confirmation route require `users.delete`, but the destructive sink only authorizes `up

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vgx7-c78r-69w9