{"id":"CVE-2026-48493","title":"Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment","summary":"Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment","severity":"medium","cvss":5.5,"cwe":["CWE-863"],"vendor":"snipe","product":"snipe/snipe-it","ecosystem":"composer","affected":["snipe/snipe-it < 8.6.0"],"patched":["snipe/snipe-it 8.6.0"],"published":"2026-06-23","updated":"2026-06-23","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-52fw-7fw2-fmv5","references":[{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-52fw-7fw2-fmv5"},{"url":"https://github.com/grokability/snipe-it/pull/19024"},{"url":"https://github.com/advisories/GHSA-52fw-7fw2-fmv5"}],"tags":["ghsa","composer"],"epss":0.00306,"epssPercentile":0.23524,"ingestedAt":"2026-06-26T16:43:14.603Z","slug":"CVE-2026-48493","body":"## Overview\n\n### Impact\nA user with only users.edit AND api permissions can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`, `reports.view`, import, etc.\n\n### Patches\nPatched in https://github.com/grokability/snipe-it/pull/19024\n\n## Affected packages\n\n- `snipe/snipe-it < 8.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `snipe/snipe-it 8.6.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}