Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Description
Published by the National Vulnerability Database
Jun 8, 2026
Published to the GitHub Advisory Database
Jun 23, 2026
Reviewed
Jun 23, 2026
Last updated
Aug 21, 2026
Impact
The vulnerability allows a non-admin user holding only the granular
users.editpermission to lock every admin out of the instance by editing theactivatedflag (which determines whether or not a user can login) and theldap_importflag, which determines whether or not the user can request a password reset.Patches
Patched in grokability/snipe-it@403f9c8
References