Data Loss Vulnerability in Snipe-IT by Grokability
CVE-2026-86749

7HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86749?

Snipe-IT versions up to 8.6.3 are affected by a significant vulnerability that occurs during image upload processes. The application does not adequately verify the success of image storage operations, leading to potential data loss when uploads fail. This situation may arise from transient issues with the storage backend, such as network errors with S3 or permission complications in local filesystems. A failure to check the write operation results in the deletion of the previously stored image and leaves the database referencing a non-existent file, which can create inconsistencies that require intricate manual recovery. Moreover, the same problem occurs when attempting to delete images, wherein a failed delete operation can orphan files. This vulnerability impacts various models utilizing image uploads, including assets, users, and other entities within the application.

Affected Version(s)

snipe-it 0 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

christopherfi-dev
snipe
.