CVE-2026-84206: Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore
Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with the assets.edit permission can exploit it, even if that user does not have assets.delete permission. The attacker needs to be able to submit asset identifiers to the bulk restore endpoint.
Are installations running version 8.7.0 or later affected?
The issue affects Snipe-IT versions before 8.7.0. Version 8.7.0 is not identified as affected by the provided information.
What is the practical impact?
A user lacking delete rights can restore soft-deleted assets that an administrator deleted. This undermines the intended separation between edit and delete permissions, affecting asset record integrity.