SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-86748

MEDIUM · CVSS 6.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Snipe-IT versions prior to 8.7.0 are vulnerable to a flaw in the restore endpoint that allows superusers to inadvertently wipe the database by uploading corrupted or invalid backup archives. This results in permanent data loss without any recovery options, making it critical for organizations using affected versions to prioritize upgrading to mitigate this risk. Superusers and database administrators should be particularly vigilant in addressing this vulnerability to prevent catastrophic data loss.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86748
Severity
MEDIUM
CVSS
6.1
EPSS
0.30%

Original NVD Description

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

Related CVEs

Other vulnerabilities affecting the same vendor(s)