CVE-2026-86733: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in grokability snipe-it
Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST /admin/backups/restore/{filename}) without the optional `clean` sanitizer parameter — which is not applied by default because DB_SANITIZE_BY_DEFAULT is false — can execute arbitrary OS commands as the web application's operating-system user, exposing application secrets (including database credentials and APP_KEY) and allowing modification of application-writable files and data. Version 8.7.0 adds the --binary-mode flag to the client invocation.
AI Analysis
Technical Summary
CVE-2026-86733 is an OS command injection vulnerability in grokability's Snipe-IT product affecting versions before 8.7.0. The vulnerability arises because the application streams SQL entries from uploaded backup archives directly into the MySQL/MariaDB command-line client without using the --binary-mode flag. This omission causes the client to interpret lines starting with backslash commands (e.g., \!) as local shell commands. An authenticated superadministrator can exploit this by uploading a specially crafted ZIP backup and restoring it without the optional 'clean' sanitizer parameter, which is disabled by default (DB_SANITIZE_BY_DEFAULT is false). This allows execution of arbitrary OS commands as the web application's operating system user, potentially exposing sensitive application secrets such as database credentials and APP_KEY, and enabling modification of writable files and data. The issue is fixed in version 8.7.0 by adding the --binary-mode flag to the MySQL client invocation.
Potential Impact
An attacker with superadministrator authentication privileges can execute arbitrary operating system commands on the server hosting the Snipe-IT application. This can lead to exposure of sensitive application secrets including database credentials and APP_KEY, as well as unauthorized modification of application-writable files and data. The vulnerability requires authenticated access with high privileges and does not involve user interaction. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
Upgrade to Snipe-IT version 8.7.0 or later, which includes the --binary-mode flag in the MySQL client invocation to prevent interpretation of backslash commands as shell commands. Until upgrading, avoid restoring backups without the optional 'clean' sanitizer parameter enabled. Since DB_SANITIZE_BY_DEFAULT is false by default, explicitly enabling sanitization during restore operations can mitigate the risk. Monitor vendor advisories for any additional remediation guidance. Patch status is not explicitly confirmed beyond the version 8.7.0 fix; verify with vendor sources.
CVE-2026-86733: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in grokability snipe-it
Description
Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST /admin/backups/restore/{filename}) without the optional `clean` sanitizer parameter — which is not applied by default because DB_SANITIZE_BY_DEFAULT is false — can execute arbitrary OS commands as the web application's operating-system user, exposing application secrets (including database credentials and APP_KEY) and allowing modification of application-writable files and data. Version 8.7.0 adds the --binary-mode flag to the client invocation.
CVSS v4.0
Score 8.6high
Affected software
pkg:github/grokability/snipe-itRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86733 is an OS command injection vulnerability in grokability's Snipe-IT product affecting versions before 8.7.0. The vulnerability arises because the application streams SQL entries from uploaded backup archives directly into the MySQL/MariaDB command-line client without using the --binary-mode flag. This omission causes the client to interpret lines starting with backslash commands (e.g., \!) as local shell commands. An authenticated superadministrator can exploit this by uploading a specially crafted ZIP backup and restoring it without the optional 'clean' sanitizer parameter, which is disabled by default (DB_SANITIZE_BY_DEFAULT is false). This allows execution of arbitrary OS commands as the web application's operating system user, potentially exposing sensitive application secrets such as database credentials and APP_KEY, and enabling modification of writable files and data. The issue is fixed in version 8.7.0 by adding the --binary-mode flag to the MySQL client invocation.
Potential Impact
An attacker with superadministrator authentication privileges can execute arbitrary operating system commands on the server hosting the Snipe-IT application. This can lead to exposure of sensitive application secrets including database credentials and APP_KEY, as well as unauthorized modification of application-writable files and data. The vulnerability requires authenticated access with high privileges and does not involve user interaction. There is no indication of known exploits in the wild at this time.
Mitigation Recommendations
Upgrade to Snipe-IT version 8.7.0 or later, which includes the --binary-mode flag in the MySQL client invocation to prevent interpretation of backslash commands as shell commands. Until upgrading, avoid restoring backups without the optional 'clean' sanitizer parameter enabled. Since DB_SANITIZE_BY_DEFAULT is false by default, explicitly enabling sanitization during restore operations can mitigate the risk. Monitor vendor advisories for any additional remediation guidance. Patch status is not explicitly confirmed beyond the version 8.7.0 fix; verify with vendor sources.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-08T11:31:09.013Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa029c1acd9273b49d8b6b7
Added to database: 09/08/2026, 15:29:05 UTC
Last enriched: 09/08/2026, 15:37:21 UTC
Last updated: 09/09/2026, 00:34:59 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.