CVE-2026-48507: Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Impact The vulnerability allows a non-admin user holding only the granular users.edit permission to lock every admin out of the instance by editing the activated flag (which determines whether or not a user can login) and the ldapimport flag, which determines whether or not the user can request a password reset.
Patches Patched in https://github.com/grokability/snipe-it/commit/403f9c848b05274642f64450696bdcdc242a352a
Other sources
Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular users.edit permission to lock every admin out of the instance by editing the activated flag (which determines whether or not a user can login) and the ldapimport flag, which determines whether or not the user can request a password reset. Version 8.6.0 contains a patch.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 8.6.0 - Upgrade
Upgrade
grokability/snipe-itto a version that resolves this vulnerability.Fixed in 8.6.0Patch 403f9c848b05274642f64450696bdcdc242a352a
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48507?
The severity of CVE-2026-48507 is rated high with a score of 7.1.
How do I fix CVE-2026-48507?
To fix CVE-2026-48507, upgrade to Snipe-IT version 8.6.0 or later.
What impact does CVE-2026-48507 have on users?
CVE-2026-48507 allows a non-admin user to lock all admin users out of the Snipe-IT instance.
Which versions of Snipe-IT are affected by CVE-2026-48507?
CVE-2026-48507 affects all versions of Snipe-IT prior to 8.6.0.
What permissions can exploitors leverage in CVE-2026-48507?
Exploiters can leverage the 'users.edit' permission to edit user activation flags and lock admins out.