CVE-2026-86748
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
- CWE
- CWE-460
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- grokability snipe-it
- grokability snipe-it
Weakness type
Related vulnerabilities
- CVE-2026-61387 — In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not...
- CVE-2026-48524 — PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-33481 — Syft improper temporary file cleanup
- CVE-2026-20118 — Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
- CVE-2025-59399 — libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is...
- CVE-2025-32439 — pleezer allows resource exhaustion through uncollected hook script processes
- CVE-2025-30157 — Envoy crashes when HTTP ext_proc processes local replies