{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/snipe-it--8.7.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-86733"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Snipe-IT (\u003c 8.7.0)","Snipe-IT (\u003c= 8.6.3)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","cve","vulnerability","web-vulnerability","css-injection","account-takeover","cve-2026-86751","ssrf","lfi","web-application","asset-management","authentication-bypass","saml","identity-management","patch-management","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Snipe-IT"],"content_html":"\u003cp\u003eSnipe-IT versions before 8.7.0 contain a critical vulnerability (CVE-2026-86733) that allows an authenticated superadministrator to achieve arbitrary operating-system command execution. The vulnerability exists within the backup restoration process, where the application streams SQL content from an uploaded backup archive directly into the \u003ccode\u003emysql\u003c/code\u003e or \u003ccode\u003emariadb\u003c/code\u003e command-line client. Because the client is invoked without the \u003ccode\u003e--binary-mode\u003c/code\u003e flag, it interprets sequences starting with backslashes as local shell commands. An attacker with superadministrator privileges can supply a malicious ZIP archive containing a crafted SQL file to the \u003ccode\u003e/admin/backups/upload\u003c/code\u003e endpoint and trigger a restore via \u003ccode\u003ePOST /admin/backups/restore/{filename}\u003c/code\u003e. If the \u003ccode\u003eclean\u003c/code\u003e sanitizer parameter is omitted, which is the default configuration unless \u003ccode\u003eDB_SANITIZE_BY_DEFAULT\u003c/code\u003e is enabled, the embedded shell directives are executed by the underlying operating system user running the web application. This leads to full system compromise, including the exfiltration of application secrets like \u003ccode\u003eAPP_KEY\u003c/code\u003e and database credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a malicious superadministrator to execute arbitrary commands on the server hosting the Snipe-IT application. This results in the complete loss of confidentiality, integrity, and availability of the application, including access to database content, environment configuration, and potential lateral movement from the host system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Snipe-IT to version 8.7.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, ensure the \u003ccode\u003eDB_SANITIZE_BY_DEFAULT\u003c/code\u003e configuration parameter is set to \u003ccode\u003etrue\u003c/code\u003e to force sanitization during backup restoration.\u003c/li\u003e\n\u003cli\u003eRestrict access to the superadministrator role to trusted personnel only, as exploitation requires high-level administrative access.\u003c/li\u003e\n\u003cli\u003eAudit logs for \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/admin/backups/upload\u003c/code\u003e and \u003ccode\u003e/admin/backups/restore/\u003c/code\u003e to identify anomalous administrative behavior.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-09T16:58:13Z","date_published":"2026-09-08T17:45:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-snipe-it-rce/","summary":"Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.","title":"Arbitrary Command Execution in Snipe-IT Backup Restoration","url":"https://feed.craftedsignal.io/briefs/2026-09-snipe-it-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Snipe-IT (\u003c 8.7.0)","version":"https://jsonfeed.org/version/1.1"}