Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6f75-x745-xcpr | Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users |
Fri, 21 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Snipeitapp
Snipeitapp snipe-it |
|
| CPEs | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Snipeitapp
Snipeitapp snipe-it |
Mon, 08 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grokability
Grokability snipe-it |
|
| Vendors & Products |
Grokability
Grokability snipe-it |
Mon, 08 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which determines whether or not a user can login) and the `ldap_import` flag, which determines whether or not the user can request a password reset. Version 8.6.0 contains a patch. | |
| Title | Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-21T19:59:42.204Z
Reserved: 2026-05-21T16:18:10.618Z
Link: CVE-2026-48507
Updated: 2026-06-08T18:03:21.704Z
Status : Modified
Published: 2026-06-08T17:16:52.390
Modified: 2026-08-21T20:16:35.820
Link: CVE-2026-48507
No data.
OpenCVE Enrichment
Updated: 2026-06-08T20:45:32Z
Github GHSA