Description
Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files hidden from listings, but the physical files persist on disk and remain accessible to anyone with filesystem or backup access.
Published: 2026-09-09
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Inconsistent Deletion Leading to Residual Data Exposure
Action: Apply Patch
AI Analysis

Impact

Snipe‑IT versions prior to 8.7.0 contain a logic flaw in the file deletion handlers where the return status of the underlying storage deletion operation is ignored. The weakness involves ignoring the return value of a storage deletion call (CWE‑212). As a result, deletion requests return a success response even when the physical file remains on the server’s filesystem. Administrators observing the API or UI believe the attachment has been removed, yet the file is still stored and can be accessed by anyone with direct filesystem or backup access.

Affected Systems

Vendors: grokability:snipe‑it. Product: Snipe‑IT web asset management system. Affected releases: all versions earlier than 8.7.0. No specific sub‑versions are excluded; all builds in that range are impacted. The flaw is present in both the web controller and the API controller for uploaded files.

Risk and Exploitability

The flaw carries a CVSS score of 5.1, indicating moderate risk. EPSS data is unavailable, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be through an authenticated administrator or an actor who can trigger the deletion endpoint. Successful exploitation does not provide remote code execution but allows residual data to persist, potentially exposing confidential attachments if filesystem or backup credentials are compromised.

Generated by OpenCVE AI on September 9, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later where the deletion logic correctly verifies the storage operation.
  • For systems that cannot be upgraded immediately, manually locate any orphaned attachment files in the storage directory and delete them, and purge any backups that contain those files.
  • Restrict filesystem and backup access to authorized personnel only, and enforce strict access controls to prevent unauthorized reading of residual files.

Generated by OpenCVE AI on September 9, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files hidden from listings, but the physical files persist on disk and remain accessible to anyone with filesystem or backup access.
Title Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-212
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:20:06.064Z

Reserved: 2026-09-08T11:31:38.679Z

Link: CVE-2026-86740

cve-icon Vulnrichment

Updated: 2026-09-14T13:19:59.827Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:22.537

Modified: 2026-09-14T20:49:15.543

Link: CVE-2026-86740

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:45:16Z

Weaknesses
  • CWE-212

    Improper Removal of Sensitive Information Before Storage or Transfer