Back Redpacketsecurity CVE Alert: CVE-2026-86762 – grokability – snipe
Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user’s Passport personal access tokens. As a result, although a deactivated account is correctly refused at web login, its existing API token continues to authenticate and to grant read and write access to the REST API (assets, users, licenses, etc.) at the account’s prior permission level until the token expires. A deactivated account that retains user-management permissions can re-activate itself through the API, permanently defeating the deactivation control.
High operational risk: prioritise remediation promptly, although KEV, SSVC exploitation status, PoC availability and EPSS are not supplied, so active exploitation cannot be confirmed.
A former or disabled user may retain effective API access, undermining offboarding and incident-containment procedures. An attacker controlling such a token could read sensitive inventory and identity data, alter asset or licence records, manipulate users, and potentially restore the compromised account’s access.
### Most likely attack path
The practical path is network access to the REST API (AV:N), a valid low-privilege or previously issued token (PR:L), low complexity (AC:L), and no user interaction (UI:N). Scope is unchanged, so direct impact remains within the application, but privileged account-management permissions could enable persistence and create a platform for wider organisational abuse.
### Who is most exposed
Organisations using Snipe-IT as a central asset register, particularly those integrated with identity lifecycle processes, are most exposed. Risk increases where API tokens are long-lived, broadly permissioned, or issued to administrators and automation accounts.
Review API authentication logs for tokens used after account deactivation.
Alert on reactivation or privilege changes made through API endpoints.
Identify unusual bulk reads or updates to assets, users and licences.
Inventory active personal access tokens and their owners, age and scope.
### Mitigation and prioritisation
Upgrade to the vendor-fixed release as soon as change control permits; treat as an urgent high-priority patch.
Immediately revoke tokens belonging to disabled, departed or suspected-compromised users.
Apply least privilege, shorten token lifetimes and restrict API exposure through network controls.
Validate deactivation workflows, including API access, and record emergency changes for later review.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
