MEDIUMVulnerability

CVE-2026-86748

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

Properties

severity
MEDIUM
score
6.1
cve_id
CVE-2026-86748
signal_observed_at
2026-09-17T21:32:24+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
published_at
2026-09-09T14:17:23.710
last_modified
2026-09-14T20:33:09.103

Related Entities (3)

AFFECTS_PRODUCT (1)

[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Cleanup on Thrown Exception

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86748 — Ninja Signal Threat Intelligence | Ninja Signal