Количество 3
Количество 3
CVE-2026-55460
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() authorizes only update, allowing the user to soft-delete another non-admin user. This issue is fixed in version 8.6.2.
CVE-2026-55460
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an ...
GHSA-vgx7-c78r-69w9
Snipe-IT has an authorization bypass on bulk editing users
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55460 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() authorizes only update, allowing the user to soft-delete another non-admin user. This issue is fixed in version 8.6.2. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-55460 Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an ... | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-vgx7-c78r-69w9 Snipe-IT has an authorization bypass on bulk editing users | CVSS3: 7.1 | 0% Низкий | 26 дней назад |
Уязвимостей на страницу