THREAT OPS › Threat News › [GHSA] GHSA-vgx7-c78r-69w9 (high) — Snipe-IT has an authorization bypass on bulk editing users
[GHSA] GHSA-vgx7-c78r-69w9 (high) — Snipe-IT has an authorization bypass on bulk editing users
GHSA-vgx7-c78r-69w9 Severity: high CVE: CVE-2026-55460
Snipe-IT has an authorization bypass on bulk editing users
### Impact An authenticated non-admin user with `users.view` and `users.edit`, but without `users.delete`, can directly POST to `/users/bulksave` and soft-delete another non-admin user. The UI and confirmation route require `users.delete`, but the destructive sink only authorizes `up
Indicators of compromise
- CVE-2026-55460cve
Original source: https://github.com/advisories/GHSA-vgx7-c78r-69w9