CVE-2026-84206: Snipeitapp Snipe-It

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.

Affected products

  • Snipeitapp Snipe-It: before 8.7.0 (fixed in 8.7.0)

Published 2026-09-01. Last modified 2026-09-29.