Snipe-IT versions prior to 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality. Restricted users can exploit this flaw to soft-delete user accounts outside their authorized scope. Attackers craft bulk delete requests that include unauthorized user IDs, bypassing instance-level access restrictions. This allows malicious restricted users to modify or disable accounts they should not have access to. The vulnerability poses a significant risk to organizations using Snipe-IT for IT asset management, as it can lead to unauthorized account manipulation. A fix has been released in version 8.6.3, and users are advised to upgrade immediately.