CVE-2026-86748: Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Snipe-ITto a version that resolves this vulnerability.Fixed in 8.7.0 - Compensating control
Restrict access to the Snipe-IT restore endpoint/backup upload capability to trusted superusers only, to prevent uploading corrupted or invalid zip archives that could trigger the restore path.
Event History
Frequently Asked Questions
Who can trigger the database wipe?
A superuser must upload a corrupted or otherwise invalid ZIP backup archive through the restore endpoint. This is not described as exploitable by unauthenticated or lower-privileged users.
Are installations affected by default?
The issue affects Snipe-IT versions before 8.7.0 when a superuser uses the restore endpoint with an invalid backup archive. The provided data does not state whether the restore feature is enabled or exposed differently in default deployments.
What is the impact if exploitation succeeds?
The database is wiped before the uploaded archive is validated, causing permanent data loss. The vulnerability description states that there is no recovery path or rollback mechanism.
How can administrators avoid this before upgrading?
Do not upload corrupted or unverified ZIP backup archives to the restore endpoint, and restrict restore operations to trusted superusers. Ensure a separate, tested database backup is available before attempting any restore.