CVE-2026-48493: Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
A user with only users.edit AND api permissions can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example assets.view, assets.create, reports.view, import, etc.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48493 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →