
CVE-2026-38533 An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify … https://www.cve.org/CVERecord?id=CVE-2026-38533
Post summary
The text announces CVE-2026-38533, detailing an improper authorization vulnerability in Snipe-IT's user endpoint that permits authenticated attackers with users.edit permission to modify users, but it contains no PoC, exploit code, or patch information.
