CVE-2026-86740
CVE-2026-86740 is a low-severity vulnerability in Snipeitapp Snipe-it with a CVSS 3.x base score of 3.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-212.
Key facts
- Severity: Low (CVSS 3.x base score 3.8)
- CVSS v4: 5.1
- EPSS exploit prediction: 0% (20th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-212
- Affected product: Snipeitapp Snipe-it
- Published:
- Last modified:
Description
Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files hidden from listings, but the physical files persist on disk and remain accessible to anyone with filesystem or backup access.
Frequently asked questions
- What is CVE-2026-86740?
- Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files hidden from listings, but the physical files persist on disk and remain accessible to anyone with filesystem or backup access.
- How severe is CVE-2026-86740?
- CVE-2026-86740 has a CVSS 3.x base score of 3.8, rated low severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-86740 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (20th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-86740?
- CVE-2026-86740 affects Snipeitapp Snipe-it. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-86740?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-86740 published?
- CVE-2026-86740 was published on 2026-09-09 and last updated on 2026-09-14.
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-4c4h-cpgf-h4qr
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-attachment-deletion-reports-success-while-file-remains
Affected products (1)
- cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
More vulnerabilities in Snipeitapp Snipe-it
- CVE-2025-63601 — Critical (CVSS 9.9): Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to…
- CVE-2026-37709 — Critical (CVSS 9.8): Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit…
- CVE-2026-85617 — High (CVSS 8.8): snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that…
- CVE-2026-55643 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can…
- CVE-2026-55483 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission…
- CVE-2026-44832 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit…
All CVEs affecting Snipeitapp Snipe-it →
Other CWE-212 vulnerabilities
- CVE-2022-2818 — Critical (CVSS 9.8): Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to…
- CVE-2020-11684 — Critical (CVSS 9.1): AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control…
- CVE-2026-85094 — High (CVSS 8.8): The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a…
- CVE-2026-39937 — High (CVSS 8.8): Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation…
- CVE-2022-30617 — High (CVSS 8.8): An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and…
- CVE-2022-0355 — High (CVSS 8.8): Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.