Beveiligingsadvies

CVE-2026-38533

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-14 00:00:00
Laatst bijgewerkt 2026-04-16 12:06:16
Toegewezen door mitre
CVSS-score 6.5
Status PUBLISHED

Beschrijving

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.