Improper access control in snipe-it - #VU134510
Published: June 15, 2026
snipe-it
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the web and API UsersController store() method when creating a new user account. A remote user can create a new user with admin privileges to escalate privileges.
This issue affects authenticated users who have the users.create permission.