Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
Moderate severity
GitHub Reviewed
Published
Jun 24, 2026
in
grokability/snipe-it
•
Updated Aug 28, 2026
Description
Published by the National Vulnerability Database
Jul 10, 2026
Published to the GitHub Advisory Database
Aug 28, 2026
Reviewed
Aug 28, 2026
Last updated
Aug 28, 2026
Impact
The route POST
/account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?}acceptscancel_by_adminas a plain URL path segment with no authorization check. Any authenticated user regardless of permissions can set this parameter to a truthy value and supply a victim's user ID to silently cancel that user's pending asset requests. The attacker only needs an active session; no elevated privilege is required.Patches
Patched in 8.6.1
References