Snipe-IT API Access Vulnerability Exposes Deactivated User Tokens
Article Content
A critical vulnerability in Snipe-IT, identified as CVE-2026-86762, allows deactivated users to retain their REST API access tokens, granting them read and write permissions even after account deactivation. This flaw arises because the CheckUserIsActivated middleware is not applied to the API middleware group, meaning that while web login is blocked, API access remains intact. Consequently, offboarded employees or compromised accounts can still manipulate sensitive inventory data until the tokens expire. The vulnerability affects all versions of Snipe-IT prior to 8.7.0. Organizations using Snipe-IT, especially those with integrated identity lifecycle processes, are at high risk. Immediate remediation is advised, including revoking tokens and upgrading to the fixed release. The vulnerability was published on September 9, 2026, and is currently unconfirmed for active exploitation.
Key Points: • CVE-2026-86762 allows deactivated users to retain API access tokens. • The vulnerability affects all Snipe-IT versions before 8.7.0. • Immediate remediation is necessary to prevent unauthorized access.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.