CVE-2026-86748
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | 0 < 8.7.0 | affected |
| grokability | snipe-it | 8.7.0 | unaffected |
Weaknesses
- CWE-460: Improper Cleanup on Thrown Exception
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-database-wipe-via-invalid-backup-archive
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.