CVE-2026-86760 | Grokability Snipe-IT up to 8.6.x User Edit Route UsersController.php update activated improper authorization
A vulnerability, which was classified as problematic, has been found in Grokability Snipe-IT up to 8.6.x. This vulnerability affects the function app/Http/Controllers/Users/UsersController::update of the file app/Http/Controllers/Users/UsersController.php of the component User Edit Route. Performing a manipulation of the argument activated results in improper authorization.
This vulnerability is known as CVE-2026-86760. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More