CVE-2026-55460 | grokability Snipe-IT up to 8.6.1 Bulk User Management destroy delete_user improper authorization

SecurityVulns

A vulnerability was found in grokability Snipe-IT up to 8.6.1. It has been rated as critical. Affected by this issue is the function BulkUsersController::destroy of the component Bulk User Management. This manipulation of the argument delete_user causes improper authorization.

This vulnerability is tracked as CVE-2026-55460. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More