CVE-2026-86748
Analyzed Analyzed - Analysis Complete

Snipe-IT Database Wipe via Invalid Backup Upload

Vulnerability report for CVE-2026-86748, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-460 The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86748 affects Snipe-IT versions before 8.7.0. The vulnerability occurs in the restore endpoint where superusers upload corrupted or invalid ZIP files. The system wipes the database before validating the backup archive, causing permanent data loss with no recovery path. The restore process fails silently, leaving an empty schema and no way to restore data.

Detection Guidance

Check Snipe-IT version with: grep -r "version" /path/to/snipe-it/config/app.php. If version is 8.6.3 or earlier, the system is vulnerable. Review restore endpoint logs for failed restore attempts with corrupted ZIP files.

Impact Analysis

If you are a superuser using Snipe-IT versions before 8.7.0, uploading a corrupted backup file will permanently delete your database. There is no rollback or recovery mechanism, leading to complete data loss and system unavailability. The vulnerability requires high privileges but is triggered by legitimate actions.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to permanent data loss. GDPR requires data integrity and availability, while HIPAA mandates secure data handling and recovery. Losing critical data violates these regulations, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. Avoid uploading backup archives until the upgrade is complete. Ensure superusers are aware of the risk of corrupted files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86748. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart