CVE-2026-38533 is an improper authorization vulnerability affecting Snipe-IT version 8.4.0 in the /api/v1/users/{id} endpoint that permits authenticated users with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users through a crafted PUT request. This vulnerability requires an authenticated attacker to exploit it, making it inaccessible to unauthenticated threat actors. The attack has a CVSS severity rating of 6.5 (Medium) with a network-based attack vector, low complexity, and low privilege requirements, with the primary impact being integrity compromise of user accounts. The vulnerability is not currently listed on the KEV catalog and shows very low exploitation probability with an EPSS score of 0.00047, indicating minimal real-world exploitation activity. Community attention remains low, with the vulnerability classified as inactive on threat tracking lists, suggesting limited public awareness or active exploit development at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.4.0CPE matchmatch criteria | cpe:2.3:a:snipeitapp:snipe-it:8.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.