Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which determines whether or not a user can login) and the `ldap_import` flag, which determines whether or not the user can request a password reset. Version 8.6.0 contains a patch.
References
Configurations
History
No history.
Information
Published : 2026-06-08 17:16
Updated : 2026-08-21 20:16
NVD link : CVE-2026-48507
Mitre link : CVE-2026-48507
CVE.ORG link : CVE-2026-48507
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-863
Incorrect Authorization
