MEDIUM 6.9 NVD
CVE-2026-86748
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invali
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-database-wipe-via-invalid-backu
- https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-09-09 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.