Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-86733: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in grokability snipe-it

0
High
VulnerabilityCVE-2026-86733cvecve-2026-86733
Published: 09/08/2026 (09/08/2026, 15:14:03 UTC)
Source: CVE Database V5
Vendor/Project: grokability
Product: snipe-it

Description

Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST /admin/backups/restore/{filename}) without the optional `clean` sanitizer parameter — which is not applied by default because DB_SANITIZE_BY_DEFAULT is false — can execute arbitrary OS commands as the web application's operating-system user, exposing application secrets (including database credentials and APP_KEY) and allowing modification of application-writable files and data. Version 8.7.0 adds the --binary-mode flag to the client invocation.

CVSS v4.0

Score 8.6high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
High
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →ai
grokability/snipe-it
pkg:github/grokability/snipe-it
Affected versions
<8.7.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 15:37:21 UTC

Technical Analysis

CVE-2026-86733 is an OS command injection vulnerability in grokability's Snipe-IT product affecting versions before 8.7.0. The vulnerability arises because the application streams SQL entries from uploaded backup archives directly into the MySQL/MariaDB command-line client without using the --binary-mode flag. This omission causes the client to interpret lines starting with backslash commands (e.g., \!) as local shell commands. An authenticated superadministrator can exploit this by uploading a specially crafted ZIP backup and restoring it without the optional 'clean' sanitizer parameter, which is disabled by default (DB_SANITIZE_BY_DEFAULT is false). This allows execution of arbitrary OS commands as the web application's operating system user, potentially exposing sensitive application secrets such as database credentials and APP_KEY, and enabling modification of writable files and data. The issue is fixed in version 8.7.0 by adding the --binary-mode flag to the MySQL client invocation.

Potential Impact

An attacker with superadministrator authentication privileges can execute arbitrary operating system commands on the server hosting the Snipe-IT application. This can lead to exposure of sensitive application secrets including database credentials and APP_KEY, as well as unauthorized modification of application-writable files and data. The vulnerability requires authenticated access with high privileges and does not involve user interaction. There is no indication of known exploits in the wild at this time.

Mitigation Recommendations

Upgrade to Snipe-IT version 8.7.0 or later, which includes the --binary-mode flag in the MySQL client invocation to prevent interpretation of backslash commands as shell commands. Until upgrading, avoid restoring backups without the optional 'clean' sanitizer parameter enabled. Since DB_SANITIZE_BY_DEFAULT is false by default, explicitly enabling sanitization during restore operations can mitigate the risk. Monitor vendor advisories for any additional remediation guidance. Patch status is not explicitly confirmed beyond the version 8.7.0 fix; verify with vendor sources.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-08T11:31:09.013Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6aa029c1acd9273b49d8b6b7

Added to database: 09/08/2026, 15:29:05 UTC

Last enriched: 09/08/2026, 15:37:21 UTC

Last updated: 09/09/2026, 00:34:59 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses