Description
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Published: 2026-09-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Permanent Database Data Loss
Action: Immediate Patch
AI Analysis

Impact

Snipe‑IT versions prior to 8.7.0 delete all database records before verifying the integrity of an uploaded backup archive in the restore endpoint. An attacker with superuser privileges who uploads a corrupted or invalid ZIP triggers a complete, irreversible wipe of the database, leaving no recovery or rollback path. This flaw combines improper input validation with privileged execution, resulting in permanent loss of inventory and asset information.

Affected Systems

The affected product is Snipe‑IT, a web‑based asset management solution from the vendor grokability. Versions earlier than 8.7.0 are impacted; no specific sub‑versions are listed, so all releases before the 8.7.0 release are vulnerable.

Risk and Exploitability

The CVSS score is 6.9, indicating a medium severity vulnerability. Because the exploitation requires superuser credentials, the risk is limited to environments where attackers can reach privileged accounts or successfully compromise them. The EPSS score is not available, but the lack of a KEV listing suggests no public exploitation yet. If a superuser account is compromised, an attacker can upload a manipulated backup archive and trigger the fatal database wipe, causing irreversible data loss. The risk therefore is moderate to high in high‑privilege scenarios.

Generated by OpenCVE AI on September 9, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later to enforce pre‑validation of backup archives.
  • Restrict the restore function to trusted administrators and enforce strict control over superuser credentials.
  • Maintain separate, regularly updated backups of the database and ensure a recovery point exists before initiating any restore operation.

Generated by OpenCVE AI on September 9, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Title Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-460
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:27:21.152Z

Reserved: 2026-09-08T11:32:11.095Z

Link: CVE-2026-86748

cve-icon Vulnrichment

Updated: 2026-09-09T14:27:00.715Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:23.710

Modified: 2026-09-14T20:33:09.103

Link: CVE-2026-86748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:30:17Z

Weaknesses
  • CWE-460

    Improper Cleanup on Thrown Exception