PT-2026-39300 · Git+3 · Snipe-It+1

·

CVE-2026-44832

·

Published

2026-05-08

·

Updated

2026-07-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.4.1
Description An authenticated user possessing only the users.edit permission can escalate their privileges to administrator. This occurs by sending a PATCH request to the '/api/v1/users/{id}' endpoint with the permissions[admin] variable set to 1. The API controller fails to properly validate the permissions array, stripping only the superuser key while allowing the admin and other permission keys to be modified by any user with update capabilities.
Recommendations Update to version 8.4.1.

Exploit

Fix

LPE

Improper Preservation of Permissions

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44832
GHSA-HQ28-CRG7-95PR

Affected Products

Snipe-It
Snipe/Snipe-It