Medium severity6.1NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-86748
CVE-2026-86748
Description
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Affected products
2- Range: <8.7.0
- Range: <8.7.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.