---
cve: "CVE-2026-86733"
severity: "HIGH"
cvss: 8.6
epss: "0.3%"
vendor: "grokability"
kev: false
exploited: false
published: "2026-09-08 15:14:03"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T03:40:03+02:00"
---

# CVE-2026-86733

> 8.6 HIGH · 🧪 PoC

## Beschreibung

Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST /admin/backups/restore/{filename}) without the optional `clean` sanitizer parameter — which is not applied by default because DB_SANITIZE_BY_DEFAULT is false — can execute arbitrary OS commands as the web application's operating-system user, exposing application secrets (including database credentials and APP_KEY) and allowing modification of application-writable files and data. Version 8.7.0 adds the --binary-mode flag to the client invocation.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 1d05a7ce11e6bf9448c067ac3ffbe5e63882888e (Commit)

## Referenzen

- <https://github.com/grokability/snipe-it/security/advisories/GHSA-x53f-48vj-c5fc>
- <https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-remote-code-execution-via-backup-restore>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-86733) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
