CVE-2026-86760 | Grokability Snipe-IT up to 8.6.x User Edit Route UsersController.php update activated improper authorization

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Grokability Snipe-IT up to 8.6.x. This vulnerability affects the function app/Http/Controllers/Users/UsersController::update of the file app/Http/Controllers/Users/UsersController.php of the component User Edit Route. Performing a manipulation of the argument activated results in improper authorization.

This vulnerability is known as CVE-2026-86760. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More