An improper authorization vulnerability in the /api/v1...
Moderate severity
Unreviewed
Published
Apr 14, 2026
to the GitHub Advisory Database
•
Updated Apr 16, 2026
Description
Published by the National Vulnerability Database
Apr 14, 2026
Published to the GitHub Advisory Database
Apr 14, 2026
Last updated
Apr 16, 2026
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
References