Impact
The bulk delete operation in Snipe‑IT versions prior to 8.6.3 permits users with limited permissions to mark other users as deleted. By supplying unauthorized user identifiers in a bulk delete request, a malicious actor can cause those accounts to be deactivated or hidden from the system. This directly violates the intended access control model, allowing attackers to manipulate user data they are not entitled to manage. The underlying weakness, listed as CWE‑639, reflects an authorization bypass that can lead to loss of confidentiality, integrity, and availability of user information.
Affected Systems
Snipe‑IT instances running versions earlier than 8.6.3 are affected; the vulnerability resides in the bulk delete functionality and applies to all users of the application, regardless of role, within the scope of the installation.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. No EPSS score is available, so the exploitation probability is unspecified, but the absence of KEV listing and the lack of a publicly known exploit suggest the threat is moderate until a public exploit is discovered. The attack vector is most likely through the application’s backend API or web interface, requiring the attacker to be authenticated but not an administrator. Once the bulk delete request is crafted, the bypass allows the attacker to affect accounts outside their authorized scope, potentially disabling critical user accounts. Overall, the risk is significant, especially for installations that expose the bulk delete feature to non‑admin users or rely on the default role configuration.
OpenCVE Enrichment