ZeroHour

CVE-2026-86748

PoC moderate

Database Wipe on Invalid Backup Restore in Snipe-IT before 8.7.0

CVSS 4.0
6.9 medium
EPSS
<1%p24
Published
()
Modified
AI analysis

Snipe-IT versions before 8.7.0 destroy the application database before validating the uploaded backup archive in the restore endpoint, so restoring a corrupted or invalid zip file permanently erases all data with no rollback mechanism (CWE-460, improper cleanup). The flaw is triggered via the network-accessible restore function, but it requires superuser privileges and user interaction, meaning exploitation realistically means a privileged admin being tricked into restoring a malicious or damaged archive, or accidental data loss from a bad backup. The impact is high integrity and availability loss — total, unrecoverable destruction of asset inventory data — with no gain of confidentiality. All self-hosted Snipe-IT asset-management deployments running versions prior to 8.7.0 are affected. Exploitation likelihood is low (EPSS 0.3%, percentile 23, not in CISA KEV); a vendor security advisory (GHSA-4cr5-3hw8-8w5f) is public, but no in-the-wild attacks are known.

What to do: Upgrade Snipe-IT to version 8.7.0 or later, where the backup archive is validated before any database wipe occurs. Maintain regular, tested backups stored outside the Snipe-IT server itself, since the bug destroys data with no recovery path. Restrict superuser access and verify the integrity of any backup zip before attempting a restore on vulnerable versions.

Affected
snipeitapp snipe-itbefore 8.7.0
Estimated exposure
moderatelow thousands of internet-exposed Snipe-IT instances, likely low tens of thousands of deployments including internal ones — Snipe-IT is a self-hosted open-source asset management tool with a large GitHub following; public internet scans (Shodan/FOFA) typically show a few thousand exposed instances, while most deployments sit on internal networks, so total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

Vendors
snipeitapp
Products
snipe-it
Weakness
CWE-460
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.