MEDIUMVulnerability
CVE-2026-86748
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.
Properties
- severity
- MEDIUM
- score
- 6.1
- cve_id
- CVE-2026-86748
- signal_observed_at
- 2026-09-17T21:32:24+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
- published_at
- 2026-09-09T14:17:23.710
- last_modified
- 2026-09-14T20:33:09.103
Related Entities (3)
AFFECTS_PRODUCT (1)
→[Product]
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Improper Cleanup on Thrown Exception
Explore deeper with Ninja Signal's threat intelligence graph