Snipe-IT API Access Vulnerability Exposes Deactivated User Tokens

Snipe-IT API Access Vulnerability Exposes Deactivated User Tokens

First seen 10 Sep 2026, 10:43 UTC Redpacketsecuritygithub.com 65.2

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Snipe-IT, identified as CVE-2026-86762, allows deactivated users to retain their REST API access tokens, granting them read and write permissions even after account deactivation. This flaw arises because the CheckUserIsActivated middleware is not applied to the API middleware group, meaning that while web login is blocked, API access remains intact. Consequently, offboarded employees or compromised accounts can still manipulate sensitive inventory data until the tokens expire. The vulnerability affects all versions of Snipe-IT prior to 8.7.0. Organizations using Snipe-IT, especially those with integrated identity lifecycle processes, are at high risk. Immediate remediation is advised, including revoking tokens and upgrading to the fixed release. The vulnerability was published on September 9, 2026, and is currently unconfirmed for active exploitation.

Key Points: • CVE-2026-86762 allows deactivated users to retain API access tokens. • The vulnerability affects all Snipe-IT versions before 8.7.0. • Immediate remediation is necessary to prevent unauthorized access.

Ask AI about this cluster

Timeline

2026-09-09
CVE-2026-86762 published
Snipe-IT vulnerability disclosed, allowing deactivated users to retain API access tokens.
Redpacketsecurity
2026-09-10
Vulnerability acknowledged
Snipe-IT confirms the flaw and outlines the implications for user access and data security.
github.com