Description
Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.
Published: 2026-09-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass leading to unintended asset restoration and privilege escalation (CWE-863)
Action: Immediate Patch
AI Analysis

Impact

Snipe‑IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users with edit rights to restore soft‑deleted assets. The flaw is an access‑control issue (CWE‑863) that undermines data integrity, audit trails, and effectively grants privilege escalation for users who do not have delete permissions.

Affected Systems

All releases of the Snipe‑IT web application prior to version 8.7.0, as implemented by grokability. The vulnerability resides in the BulkAssetsController and affects any deployment using an 8.6.x (or earlier) build.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate risk. No EPSS value is provided, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a web request to the bulk restore API that requires an authenticated session with assets.edit permission; an attacker can supply asset identifiers and reverse administrator deletions, bypassing intended permission separation.

Generated by OpenCVE AI on September 2, 2026 at 03:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later to correct the authorization check.
  • Restrict the assets.edit role to trusted users, and re‑evaluate whether that permission is necessary for all users.
  • Enable or review audit logging for the bulk restore endpoint to detect unauthorized restoration activity.

Generated by OpenCVE AI on September 2, 2026 at 03:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.
Title Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-04T02:02:48.181Z

Reserved: 2026-09-01T11:03:27.973Z

Link: CVE-2026-84206

cve-icon Vulnrichment

Updated: 2026-09-04T02:02:42.308Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T16:17:35.607

Modified: 2026-09-10T15:43:03.760

Link: CVE-2026-84206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:15:04Z

Weaknesses