CVE-2026-86748: Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive

Published Sep 9, 2026
·
Updated

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

Affected Software

1 affected component
snipe-it<8.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Fixed in 8.7.0
  2. Compensating control

    Restrict access to the Snipe-IT restore endpoint/backup upload capability to trusted superusers only, to prevent uploading corrupted or invalid zip archives that could trigger the restore path.

Event History

Sep 9, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can trigger the database wipe?

A superuser must upload a corrupted or otherwise invalid ZIP backup archive through the restore endpoint. This is not described as exploitable by unauthenticated or lower-privileged users.

2

Are installations affected by default?

The issue affects Snipe-IT versions before 8.7.0 when a superuser uses the restore endpoint with an invalid backup archive. The provided data does not state whether the restore feature is enabled or exposed differently in default deployments.

3

What is the impact if exploitation succeeds?

The database is wiped before the uploaded archive is validated, causing permanent data loss. The vulnerability description states that there is no recovery path or rollback mechanism.

4

How can administrators avoid this before upgrading?

Do not upload corrupted or unverified ZIP backup archives to the restore endpoint, and restrict restore operations to trusted superusers. Ensure a separate, tested database backup is available before attempting any restore.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203