CVE-2026-84206 UNKNOWN

CVE-2026-84206

Published: 2026-09-01

Description

Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…