CVE-2026-48493Medium· 5.5▾ SunlitSnipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
A user with only users.edit AND api permissions can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example assets.view, assets.create, reports.view, import, etc.
Patched in https://github.com/grokability/snipe-it/pull/19024
snipe/snipe-it < 8.6.0Upgrade to a patched release:
snipe/snipe-it 8.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users
CVE-2026-55472Medium· 4.3Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
CVE-2026-48507High· 7.1Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
CVE-2026-49976Medium· 6.5Snipe-IT is an IT asset/license management system
CVE-2026-50550Medium· 5.8Snipe-IT is an IT asset/license management system
CVE-2022-23064High· 8.8snipe-IT vulnerable to host header injection