Skip to main content
Vulnerability Database/CVE-2026-86733

CVE-2026-86733: Snipeitapp Snipe-it RCE Vulnerability

CVE-2026-86733 is a remote code execution vulnerability in Snipeitapp Snipe-it that lets authenticated superadmins execute arbitrary OS commands through crafted backup files. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-86733 Overview

CVE-2026-86733 is a command injection vulnerability in Snipe-IT, an open-source IT asset management platform. Versions before 8.7.0 stream SQL content from uploaded backup archives directly into the MySQL/MariaDB command-line client without the --binary-mode flag. The client interprets lines beginning with backslash commands such as \! as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup and triggers a restore can execute arbitrary operating system commands as the web application user. The flaw is tracked under CWE-78: OS Command Injection.

Critical Impact

Successful exploitation exposes application secrets including database credentials and APP_KEY, and allows modification of any application-writable files and data.

Affected Products

  • Snipe-IT versions prior to 8.7.0
  • Snipe-IT deployments with DB_SANITIZE_BY_DEFAULT set to false (the default)
  • Self-hosted Snipe-IT instances exposing /admin/backups/upload and /admin/backups/restore/{filename} endpoints

Discovery Timeline

  • 2026-09-08 - CVE-2026-86733 published to NVD
  • 2026-09-09 - Last updated in NVD database

Technical Details for CVE-2026-86733

Vulnerability Analysis

Snipe-IT provides a backup and restore workflow for superadministrators. When a restore is triggered, the application streams the SQL dump from the uploaded archive directly into the mysql command-line client. Without the --binary-mode flag, the client parses each input line for interactive client directives.

The MySQL/MariaDB client treats lines starting with \! as shell escape sequences. Any command following \! is executed by the client's parent shell as the operating system user running the restore process, which is the web application's user account. Because the SQL content originates from an attacker-controlled ZIP archive, a superadministrator's restore action becomes an arbitrary command execution primitive.

By default, Snipe-IT ships with DB_SANITIZE_BY_DEFAULT set to false, meaning the optional clean sanitizer parameter that could strip such sequences is not applied unless explicitly requested. This default configuration widens the exposure window.

Root Cause

The root cause is unsafe invocation of an external interpreter. The application trusts backup archive contents and pipes them into mysql without disabling the client's interactive metacommand parser. --binary-mode disables backslash commands and ensures input is treated as raw SQL bytes, but that flag was absent from the client invocation.

Attack Vector

An authenticated attacker with superadministrator privileges crafts a ZIP archive containing a SQL file with embedded \! shell directives. The attacker uploads the archive via POST /admin/backups/upload and then issues POST /admin/backups/restore/{filename} without setting the clean parameter. During restore, the mysql client interprets the malicious lines and executes the embedded shell commands as the web application user, exposing .env secrets, database credentials, and the Laravel APP_KEY.

No public proof-of-concept or exploit code is currently available for this issue. Refer to the VulnCheck Advisory for Snipe-IT for additional technical detail.

Detection Methods for CVE-2026-86733

Indicators of Compromise

  • Unexpected POST requests to /admin/backups/upload followed shortly by POST /admin/backups/restore/{filename} in web server access logs
  • Child processes of the web server user (www-data, nginx, apache) spawning shells such as sh, bash, or utilities like curl, wget, or nc during a restore operation
  • New or modified files in the Snipe-IT storage or configuration directories with recent timestamps that correlate to a restore event
  • Outbound network connections initiated by the PHP or web server process to unfamiliar destinations following a backup restore

Detection Strategies

  • Alert on process lineage where mysql or the Snipe-IT PHP process spawns a shell interpreter or command-line downloader
  • Monitor SQL backup files for lines beginning with \!, system, or other MySQL client metacommands prior to import
  • Correlate authenticated superadministrator session activity with subsequent backup and restore endpoint access

Monitoring Recommendations

  • Enable verbose audit logging on the Snipe-IT admin panel to capture backup upload and restore actions with user attribution
  • Forward web server, PHP-FPM, and host process telemetry to a centralized log platform for behavioral analysis
  • Baseline expected backup restore activity and alert on out-of-hours or unusual-source restore operations

How to Mitigate CVE-2026-86733

Immediate Actions Required

  • Upgrade Snipe-IT to version 8.7.0 or later, which adds the --binary-mode flag to the mysql client invocation
  • Audit superadministrator accounts and revoke unnecessary privileges to reduce the pool of users able to reach the backup restore endpoints
  • Review web server and application logs for prior restore operations and validate the integrity of .env, database credentials, and APP_KEY values
  • Rotate database credentials and the Laravel APP_KEY if any suspicious restore activity is identified

Patch Information

Snipe-IT 8.7.0 remediates the vulnerability by adding the --binary-mode flag to the MySQL client invocation, which disables interpretation of backslash metacommands. Details are available in the GitHub Security Advisory GHSA-x53f-48vj-c5fc.

Workarounds

  • Set DB_SANITIZE_BY_DEFAULT=true in the application .env file so the sanitizer is applied to all restore operations
  • Restrict network access to the /admin/backups/ routes using a reverse proxy or web application firewall until the patch is applied
  • Enforce multi-factor authentication for all superadministrator accounts to reduce the risk of credential compromise leading to exploitation
bash
# Configuration example: enforce sanitizer as a temporary mitigation
# In the Snipe-IT .env file:
DB_SANITIZE_BY_DEFAULT=true

# Then restart the application workers
php artisan config:clear
php artisan cache:clear

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.