Improper File Deletion in Snipe-IT Results in Data Exposure
CVE-2026-86740

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86740?

Snipe-IT versions prior to 8.7.0 contain a vulnerability where the application fails to properly validate the completion of file deletion processes via Storage::delete(). As a result, administrators may receive misleading success notifications after attempting to delete files. Although these files may no longer appear in the application's user interface, they remain on the server, accessible to individuals with the necessary filesystem or backup access. This flaw poses a significant risk of unintended data exposure, potentially allowing sensitive information to be retrieved even after perceived deletion.

Affected Version(s)

snipe-it 0 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

christopherfi-dev
snipe
.