CVE-2026-86748
PoC moderateDatabase Wipe on Invalid Backup Restore in Snipe-IT before 8.7.0
Snipe-IT versions before 8.7.0 destroy the application database before validating the uploaded backup archive in the restore endpoint, so restoring a corrupted or invalid zip file permanently erases all data with no rollback mechanism (CWE-460, improper cleanup). The flaw is triggered via the network-accessible restore function, but it requires superuser privileges and user interaction, meaning exploitation realistically means a privileged admin being tricked into restoring a malicious or damaged archive, or accidental data loss from a bad backup. The impact is high integrity and availability loss — total, unrecoverable destruction of asset inventory data — with no gain of confidentiality. All self-hosted Snipe-IT asset-management deployments running versions prior to 8.7.0 are affected. Exploitation likelihood is low (EPSS 0.3%, percentile 23, not in CISA KEV); a vendor security advisory (GHSA-4cr5-3hw8-8w5f) is public, but no in-the-wild attacks are known.
What to do: Upgrade Snipe-IT to version 8.7.0 or later, where the backup archive is validated before any database wipe occurs. Maintain regular, tested backups stored outside the Snipe-IT server itself, since the bug destroys data with no recovery path. Restrict superuser access and verify the integrity of any backup zip before attempting a restore on vulnerable versions.
| snipeitapp snipe-it | before 8.7.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
- Vendors
- snipeitapp
- Products
- snipe-it
- Weakness
- CWE-460
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.