When one missing unset() grants admin: CVE-2026-44832 in Snipe-IT
How a single unset('superuser') — with no equivalent for admin — let any user holding the users.edit permission self-assign admin over the API and take full control of Snipe-IT ≤ 8.4.0.