Improper access control in snipe-it - #VU142578
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to delete users outside their authorized scope.
The vulnerability exists due to improper access control in the bulk user delete functionality when handling bulk delete requests. A remote user can include unauthorized user IDs in a bulk delete payload to delete users outside their authorized scope.
The issue results in soft-deletion of targeted users and can affect users in other companies or higher-privileged users.