Impact
Snipe‑IT versions prior to 8.7.0 delete all database records before verifying the integrity of an uploaded backup archive in the restore endpoint. An attacker with superuser privileges who uploads a corrupted or invalid ZIP triggers a complete, irreversible wipe of the database, leaving no recovery or rollback path. This flaw combines improper input validation with privileged execution, resulting in permanent loss of inventory and asset information.
Affected Systems
The affected product is Snipe‑IT, a web‑based asset management solution from the vendor grokability. Versions earlier than 8.7.0 are impacted; no specific sub‑versions are listed, so all releases before the 8.7.0 release are vulnerable.
Risk and Exploitability
The CVSS score is 6.9, indicating a medium severity vulnerability. Because the exploitation requires superuser credentials, the risk is limited to environments where attackers can reach privileged accounts or successfully compromise them. The EPSS score is not available, but the lack of a KEV listing suggests no public exploitation yet. If a superuser account is compromised, an attacker can upload a manipulated backup archive and trigger the fatal database wipe, causing irreversible data loss. The risk therefore is moderate to high in high‑privilege scenarios.
OpenCVE Enrichment