CVE-2026-48492Disclosure(snipeitapp / snipe-it)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API token or elevated permissions are required. This exposes usernames, display names, employee numbers, and user IDs for every active account in the system if FMCS is not enabled, and within the company they belong to if FMCS is enabled. Version 8.6.1 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • snipe-it

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
snipe-it

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-23: 1Mentions · 2026-07-13: 1Technical Details · 2026-07-13: 106-2307-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Snipe-IT, Authorization Bypass, #CVE-2026-48492 (Medium) -DC-Jul2026-889 https://dailycve.com/snipe-it-authorization-bypass-cve-2026-48492-medium-dc-jul2026-889/

    Post summary

    The post is a straightforward disclosure of the CVE‑2026‑48492 authorization bypass in Snipe‑IT with basic technical details but no evidence of exploitation, PoC, or mitigation information.

    0000050
    218 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 Snipe-IT Improper Access Control Vulnerability #CVE-2026-48492 (Low) -DC-Jun2026-614 https://dailycve.com/snipe-it-improper-access-control-vulnerability-cve-2026-48492-low-dc-jun2026-614/

    Post summary

    The post announces CVE-2026-48492, an improper access control flaw in Snipe-IT, but provides no further exploit details, patch information, or technical depth.

    0000042
    216 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsnipeitappsnipe-it---

Explore more