CVE Explorer
CVE-2026-48492
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API token or elevated permissions are required. This exposes usernames, display names, employee numbers, and user IDs for every active account in the system if FMCS is not enabled, and
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"snipe-it","vendor":"grokability","versions":[{"status":"affected","version":"< 8.5.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d06643649d5bbac849bfc968639646862510609fee1b0d112509c3e07134fb66 · sha256:a768244846c763d0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":4.9,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d06643649d5bbac849bfc968639646862510609fee1b0d112509c3e07134fb66 · sha256:a768244846c763d0… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d06643649d5bbac849bfc968639646862510609fee1b0d112509c3e07134fb66 · sha256:a768244846c763d0… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/grokability/snipe-it/commit/4f943d4a7ab8e53f3d9e32770602d1118bab005f","tags":["x_refsource_MISC"],"url":"https://github.com/grokability/snipe-it/commit/4f943d4a7ab8e53f3d9e32770602d1118bab005f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d06643649d5bbac849bfc968639646862510609fee1b0d112509c3e07134fb66 · sha256:a768244846c763d0… · /containers/cna/references/1
{"name":"https://github.com/grokability/snipe-it/security/advisories/GHSA-f3c5-6cw8-fg57","tags":["x_refsource_CONFIRM"],"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-f3c5-6cw8-fg57"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d06643649d5bbac849bfc968639646862510609fee1b0d112509c3e07134fb66 · sha256:a768244846c763d0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.