PT-2026-89017 · Git+1 · Snipe-It

·

CVE-2026-86748

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86748
GHSA-4CR5-3HW8-8W5F

Affected Products

Snipe-It