{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-86748","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-08T11:32:11.095Z","datePublished":"2026-09-09T13:32:12.078Z","dateUpdated":"2026-09-09T14:27:21.152Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-09T13:32:12.078Z"},"datePublic":"2026-08-24T00:00:00.000Z","title":"Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive","descriptions":[{"lang":"en","value":"Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Improper Cleanup on Thrown Exception","cweId":"CWE-460","type":"CWE"}]}],"affected":[{"vendor":"grokability","product":"snipe-it","defaultStatus":"unaffected","versions":[{"version":"0","status":"affected","versionType":"semver","lessThan":"8.7.0"},{"version":"8.7.0","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*","versionEndExcluding":"8.7.0"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":6.9,"baseSeverity":"MEDIUM"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-4cr5-3hw8-8w5f)"},{"name":"VulnCheck Advisory: Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-database-wipe-via-invalid-backup-archive"}],"credits":[{"lang":"en","value":"christopherfi-dev","type":"finder"},{"lang":"en","value":"snipe","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"references":[{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-4cr5-3hw8-8w5f","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-09T14:26:54.426715Z","id":"CVE-2026-86748","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-09T14:27:21.152Z"}}]}}