Data Loss Vulnerability in Snipe-IT by Grokability
CVE-2026-86749
What is CVE-2026-86749?
Snipe-IT versions up to 8.6.3 are affected by a significant vulnerability that occurs during image upload processes. The application does not adequately verify the success of image storage operations, leading to potential data loss when uploads fail. This situation may arise from transient issues with the storage backend, such as network errors with S3 or permission complications in local filesystems. A failure to check the write operation results in the deletion of the previously stored image and leaves the database referencing a non-existent file, which can create inconsistencies that require intricate manual recovery. Moreover, the same problem occurs when attempting to delete images, wherein a failed delete operation can orphan files. This vulnerability impacts various models utilizing image uploads, including assets, users, and other entities within the application.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
