{"id":"CVE-2026-48507","aliases":["GHSA-6f75-x745-xcpr"],"url":"https://o3.security/vulnerability/CVE-2026-48507","summary":"Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users","details":"Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance  by editing the `activated` flag (which determines whether or not a user can login) and the `ldap_import` flag, which determines whether or not the user can request a password reset. Version 8.6.0 contains a patch.","published":"2026-06-08T15:41:01.840Z","modified":"2026-07-25T03:56:38.457370301Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"},"epss":{"score":0.00194,"percentile":0.09376,"asOf":"2026-08-11"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"snipe/snipe-it","fixedVersion":"8.6.0"}],"fix":{"url":"https://github.com/grokability/snipe-it/commit/403f9c848b05274642f64450696bdcdc242a352a","label":"grokability/snipe-it@403f9c8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48507.json"},{"type":"ADVISORY","url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-6f75-x745-xcpr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48507"},{"type":"FIX","url":"https://github.com/grokability/snipe-it/commit/403f9c848b05274642f64450696bdcdc242a352a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-25T03:56:38.457370301Z"}}