---
id: CVE-2026-86748
title: >-
  Snipe-IT versions before 8.7.0 wipe the database before validating the
  uploaded backup archive in the restore endpoint
summary: >-
  Snipe-IT versions before 8.7.0 wipe the database before validating the
  uploaded backup archive in the restore endpoint. Superusers uploading
  corrupted or invalid zip files trigger permanent data loss with no recovery
  path or rollback mec…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H'
cwe:
  - CWE-460
vendor: snipeitapp
product: snipe-it
affected:
  - snipe-it < 8.7.0
patched:
  - snipe-it 8.7.0
published: '2026-09-09'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:33:09.103'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86748'
references:
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-database-wipe-via-invalid-backup-archive
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00396
epssPercentile: 0.31015
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T14:26:54.426715Z'
ingestedAt: '2026-09-09T14:11:29.380Z'
---

## Overview

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

## Affected

- `snipe-it < 8.7.0`

## Remediation

Upgrade past the affected range:

- `snipe-it 8.7.0`
