CVE-2026-44832

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array, allowing admin and all other permission keys to be set by any user who can update users. This vulnerability is fixed in 8.4.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

History

26 May 2026, 20:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
First Time Snipeitapp
Snipeitapp snipe-it
References () https://github.com/grokability/snipe-it/commit/ce18ff669ceb0f0349749fd5d11c1d3d40b10569 - () https://github.com/grokability/snipe-it/commit/ce18ff669ceb0f0349749fd5d11c1d3d40b10569 - Patch
References () https://github.com/grokability/snipe-it/security/advisories/GHSA-hq28-crg7-95pr - () https://github.com/grokability/snipe-it/security/advisories/GHSA-hq28-crg7-95pr - Patch, Vendor Advisory

26 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 20:16

Updated : 2026-05-26 20:38


NVD link : CVE-2026-44832

Mitre link : CVE-2026-44832

CVE.ORG link : CVE-2026-44832


JSON object : View

Products Affected

snipeitapp

  • snipe-it
CWE
CWE-281

Improper Preservation of Permissions

CWE-863

Incorrect Authorization