FD-56664 LPE: Non-admin can modify 'activated' field via UsersController
Security Advisory
FD-56664
High
Snipe-IT
Affected:
- Snipe-IT v8.7.2 and earlier versions
Fixed in:
- Commit 02f62c8
Referenced CVEs:
CVE-2026-86760 · 5.4
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.