CVE-2026-86748EPSS p31.5%

CVE-2026-86748CVE-2026-86748

snipeitapp / snipe-it

Description

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mechanism.

Scoring

CVSS 6.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
EPSS0.40% probability of exploitation · percentile 31.5% · 2026-10-05T12:00:23Z
Last modified2026-09-14
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.