Insufficient Session Expiration in snipe-it - #VU145102

 

Insufficient Session Expiration in snipe-it - #VU145102

Published: August 25, 2026


Vulnerability identifier: #VU145102
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to retain read and write API access after account deactivation.

The vulnerability exists due to insufficient session expiration in api middleware and personal access token handling when processing authenticated REST API requests for a deactivated account. A remote user can continue using an existing personal access token to retain read and write API access after account deactivation.

A deactivated account with user-management permissions can reactivate itself through the API using its unchanged token.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins