CVE-2026-86749
Analyzed Analyzed - Analysis Complete

Data Loss in Snipe-IT Image Upload Handling

Vulnerability report for CVE-2026-86749, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-19

Assigner: VulnCheck

Description

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put(...) call still caused the application to delete the previous image via deleteExistingImage() and to reassign and persist the model's image reference to the new filename, destroying the existing image and leaving the database row pointing at a file that was never written. A mirror problem existed in deleteExistingImage(), where a failed Storage::delete() still nulled the model's image field, orphaning the file on disk. The condition is not directly attacker-controlled: it is triggered when any legitimate authenticated user submits an image upload while the storage backend transiently fails (for example an S3 network error, a local filesystem permission problem, or quota exhaustion). The result is unrecoverable loss of the prior image and a durable inconsistency between the database and disk that requires manual reconciliation. All models whose controllers route through ImageUploadRequest::handleImages (assets, asset models, users, companies, manufacturers, locations, categories, suppliers, departments, and other image-carrying models) are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-19
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-252 The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86749 affects Snipe-IT versions 8.6.3 and earlier. It involves a flaw where the system fails to check if image storage write operations succeed. When a write fails silently (e.g., due to network issues or permissions), the app deletes the existing image and updates the database to point to a non-existent file, causing data loss. A similar issue exists in the delete function, where a failed delete still removes the image reference, leaving orphaned files.

Detection Guidance

Check Snipe-IT version with: grep -r "version" /path/to/snipe-it/config/app.php. If version <= 8.6.3, the system is vulnerable. Review logs for failed storage operations during image uploads, such as 'Storage::disk("public")->put() failed' messages.

Impact Analysis

This vulnerability can lead to permanent loss of images associated with assets, users, companies, and other models in Snipe-IT. The database and disk state become inconsistent, making affected images unrenderable until manually fixed. It requires a legitimate user to trigger during a storage failure, but the impact is severe data corruption.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by causing loss or corruption of critical data (e.g., user profile images, asset records). Inconsistencies between database records and actual files may lead to unauthorized access or failure to maintain data integrity, requiring manual reconciliation to restore compliance.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. Ensure all image uploads are tested for successful storage writes before proceeding. Verify database and file system consistency after upgrades.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86749. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart