CVE-2026-86740

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files hidden from listings, but the physical files persist on disk and remain accessible to anyone with filesystem or backup access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-09 14:17

Updated : 2026-09-14 20:49


NVD link : CVE-2026-86740

Mitre link : CVE-2026-86740

CVE.ORG link : CVE-2026-86740


JSON object : View

Products Affected

snipeitapp

  • snipe-it
CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer