← Zuruck zu CVEs
CVE-2026-38533
MEDIUM6.5
Beschreibung
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht4/14/2026
Zuletzt geandert4/17/2026
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-285
Referenzen
https://snipeitapp.com/(cve@mitre.org)
https://github.com/TREXNEGRO/Security-Advisories/blob/main/CVE-2026-38533/poc.md(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.