Executive brief
Snipe-IT is an asset and inventory management system. A superadministrator can upload a malicious backup archive and restore it to execute arbitrary operating system commands with the privileges of the web application user. This exposes sensitive data (database credentials, encryption keys) and allows attackers to modify application files and data.
Technical details
The vulnerability is an OS command injection (CWE-78) in the backup restore functionality. Snipe-IT streams SQL data from uploaded ZIP backup archives directly into the MySQL/MariaDB client without the --binary-mode flag. The MariaDB client interprets lines beginning with backslash commands (e.g., `\!`) as local shell commands. An authenticated superadministrator can craft a backup archive with malicious SQL containing `\!` directives, upload it via POST /admin/backups/upload, and trigger restoration via POST /admin/backups/restore/{filename} to execute arbitrary commands as the web application's OS user. The default configuration does not sanitize the SQL input because DB_SANITIZE_BY_DEFAULT is false. The fix in version 8.7.0 adds the --binary-mode flag to disable client-side command interpretation.
Affected products
- Snipe-IT Snipe-IT before 8.7.0
Timeline
- 2026-08-16: disclosed: Vulnerability reported to Snipe-IT
- 2026-08-24: patched: Patch released in version 8.7.0
- 2026-08-24: advisory: GitHub Security Advisory GHSA-x53f-48vj-c5fc published
- 2026-09-08: other: CVE-2026-86733 assigned