CVE-2026-38533: Medium severity Snipe-IT Snipe-IT vulnerability
Published Apr 14, 2026
·Updated
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
Affected Software
2 affected components
Snipe-IT Snipe-IT=8.4.0
Snipeitapp Snipe-it=8.4.0
Event History
Apr 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-38533?
CVE-2026-38533 has a medium severity score of 6.5 according to CVSS v3.1.
2
How do I fix CVE-2026-38533?
To mitigate CVE-2026-38533, ensure that proper authorization checks are implemented for the /api/v1/users/{id} endpoint.
3
What types of attacks does CVE-2026-38533 allow?
CVE-2026-38533 allows authenticated attackers with users.edit permission to modify sensitive fields of non-admin users.
4
Which software versions are affected by CVE-2026-38533?
CVE-2026-38533 affects Snipe-IT version 8.4.0.
5
When was CVE-2026-38533 published?
CVE-2026-38533 was published on April 14, 2026.