CVE-2026-48493: medium-severity vulnerability in grokability snipe-it
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`, `reports.view`, import, etc. The issue is patched in version 8.6.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
Affected products
grokability · snipe-itRelated CVEs — grokability snipe-it
In the same product, most dangerous first.
CVE-2026-55469MEDIUMSnipe-IT: Path traversal vulnerability via CSV import `image` fieldEPSS 0.6%CVE-2026-86733HIGHSnipe-IT before 8.7.0 Remote Code Execution via Backup RestoreEPSS 0.6%CVE-2026-86770HIGHSnipe-IT before 8.7.0 Authentication Bypass via SAML Username CollationEPSS 0.6%CVE-2026-86734HIGHSnipe-IT before 8.7.1 Denial of Service via Unbounded Note FieldEPSS 0.5%CVE-2026-55843HIGHSnipe-IT: Improper Privilege ManagementEPSS 0.5%CVE-2026-86738CRITICALSnipe-IT before 8.7.0 CSS Injection via Custom CSSEPSS 0.5%