SCA: security update for snipe/snipe-it (GHSA-f3c5-6cw8-fg57)

high Tenable Self-Hosted Container Security Plugin ID 443838

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET
/api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into
Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their
web session cookie. No API token or elevated permissions are required. This exposes usernames, display
names, employee numbers, and user IDs for every active account in the system if FMCS is not enabled, and
within the company they belong to if FMCS is enabled. Version 8.6.1 contains a patch. (CVE-2026-48492)

Solution

Update the snipe/snipe-it library and its related packages to version 8.5.1 or later.

See Also

https://github.com/advisories/GHSA-f3c5-6cw8-fg57

Plugin Details

Severity: High

ID: 443838

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 6/24/2026

Updated: 7/13/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-48492

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.1

Threat Score: 4.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/23/2026

Vulnerability Publication Date: 6/23/2026

Reference Information

CVE: CVE-2026-48492

cwe: CWE-862