Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
References
| Link | Resource |
|---|---|
| https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f | Exploit Vendor Advisory Mitigation Patch |
| https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-database-wipe-via-invalid-backup-archive | Third Party Advisory |
| https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f | Exploit Vendor Advisory Mitigation Patch |
Configurations
History
No history.
Information
Published : 2026-09-09 14:17
Updated : 2026-09-14 20:33
NVD link : CVE-2026-86748
Mitre link : CVE-2026-86748
CVE.ORG link : CVE-2026-86748
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-460
Improper Cleanup on Thrown Exception
