CVE-2026-86748: Snipeitapp Snipe-It

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

Affected products

  • Snipeitapp Snipe-It: before 8.7.0 (fixed in 8.7.0)

Published 2026-09-09. Last modified 2026-09-14.