Insufficient Session Expiration in snipe-it - #VU145102
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to retain read and write API access after account deactivation.
The vulnerability exists due to insufficient session expiration in api middleware and personal access token handling when processing authenticated REST API requests for a deactivated account. A remote user can continue using an existing personal access token to retain read and write API access after account deactivation.
A deactivated account with user-management permissions can reactivate itself through the API using its unchanged token.