
CVE-2026-48493 in Snipe-IT prior to 8.6.0 allows authenticated users with users.edit permission to escalate privileges via API. https://ift.tt/Oiwx9VD
Post summary
The statement announces a privilege escalation flaw (CVE-2026-48493) in Snipe‑IT versions before 8.6.0 that allows users with edit permissions to exploit the API to gain higher privileges.


