CVE-2026-86740
Analyzed Analyzed - Analysis Complete

Snipe-IT Improper File Deletion Flaw

Vulnerability report for CVE-2026-86740, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files hidden from listings, but the physical files persist on disk and remain accessible to anyone with filesystem or backup access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86740 affects Snipe-IT versions before 8.7.0. It occurs when deleting attachments. The system calls Storage::delete() but fails to check if the file was actually removed. It reports success and hides files from listings even if they remain on disk. Physical files persist and can be accessed via filesystem or backups.

Detection Guidance

To detect this vulnerability, check if files marked as deleted in Snipe-IT still exist on disk. Use commands like 'find /path/to/uploads -type f -name "*.file_extension" -mtime -30' to search for recently deleted files. Verify if files persist after deletion attempts in the application.

Impact Analysis

This vulnerability allows sensitive files to remain on disk after deletion. Attackers with filesystem or backup access could retrieve these files. Administrators may believe files are deleted when they are not, leading to data leaks. Compliance with data deletion requests may be compromised.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR, HIPAA, and other regulations requiring proper data deletion. If files are not actually removed, organizations may fail to meet legal obligations for data erasure. This could result in fines or legal penalties due to improper handling of sensitive information.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later to fix the deletion logic. If upgrading is not possible, manually verify and remove orphaned files from the uploads directory. Ensure proper filesystem permissions prevent unauthorized access to deleted files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86740. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart