Junglewise Threat Intelligence

CVE-2026-48507: Grokability Snipe-IT incorrect authorization in bulk user editing

CVE-2026-48507 · Severity: high · CVSS 7.1 · Published 2026-06-08

Technologies: Grokability Snipe-It, snipe/snipe-it (Packagist). Vendors: Packagist.

Executive brief

A vulnerability in Snipe-IT, a popular open-source IT asset management system, allows users with limited permissions to lock administrators out of the system. By exploiting a flaw in the bulk-editing feature, a low-privileged user can deactivate administrator accounts and prevent them from resetting their passwords. This can lead to a total loss of administrative access and significant disruption to IT operations.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Snipe-IT's bulk user editing functionality. Users granted the granular 'users.edit' permission can modify the 'activated' and 'ldap_import' flags for any user, including administrators. By deactivating the 'activated' flag, an attacker can prevent login, and by modifying the 'ldap_import' flag, they can disable the ability to request password resets. This allows a low-privileged authenticated attacker to achieve a denial-of-service condition against administrative accounts. The issue is fixed in version 8.6.0.

Affected products

  • Grokability Snipe-IT < 8.6.0

Timeline

  • 2026-05-27: disclosed
  • 2026-06-08: advisory: NVD published date
  • 2026-06-23: patched: GitHub Advisory reviewed and updated

References

Related threats