CVE-2026-86748

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-09 14:17

Updated : 2026-09-14 20:33


NVD link : CVE-2026-86748

Mitre link : CVE-2026-86748

CVE.ORG link : CVE-2026-86748


JSON object : View

Products Affected

snipeitapp

  • snipe-it
CWE
CWE-460

Improper Cleanup on Thrown Exception