CVE-2026-48507High· 7.1▾ TwilightSnipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.4%
The vulnerability allows a non-admin user holding only the granular users.edit permission to lock every admin out of the instance by editing the activated flag (which determines whether or not a user can login) and the ldap_import flag, which determines whether or not the user can request a password reset.
Patched in https://github.com/grokability/snipe-it/commit/403f9c848b05274642f64450696bdcdc242a352a
snipe/snipe-it < 8.6.0Upgrade to a patched release:
snipe/snipe-it 8.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users
CVE-2026-55472Medium· 4.3Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
CVE-2026-48493Medium· 5.5Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
CVE-2026-49976Medium· 6.5Snipe-IT is an IT asset/license management system
CVE-2026-50550Medium· 5.8Snipe-IT is an IT asset/license management system
CVE-2022-23064High· 8.8snipe-IT vulnerable to host header injection