CVE-2026-86749 — Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages().
Description
Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put(...) call still caused the application to delete the previous image via deleteExistingImage() and to reassign and persist the model's image reference to the new filename, destroying the existing image and leaving the database row pointing at a file that was never written. A mirror problem existed in deleteExistingImage(), where a failed Storage::delete() still nulled the model's image field, orphaning the file on disk. The condition is not directly attacker-controlled: it is triggered when any legitimate authenticated user submits an image upload while the storage backend transiently fails (for example an S3 network error, a local filesystem permission problem, or quota exhaustion). The result is unrecoverable loss of the prior image and a durable inconsistency between the database and disk that requires manual reconciliation. All models whose controllers route through ImageUploadRequest::handleImages (assets, asset models, users, companies, manufacturers, locations, categories, suppliers, departments, and other image-carrying models) are affected.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
Low
Privileges Required
UI
Passive
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
Low
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- snipeitapp
- Product
- snipe-it
Versions
- < 8.7.0
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-106436 — The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit.
CVE-2026-106436 · 3h ago
CVE-2026-18397 — This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesse…
CVE-2026-18397 · 7d ago
CVE-2026-95316 — Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program.
CVE-2026-95316 · 9d ago
CVE-2026-67409 — RabbitMQ is a messaging and streaming broker.
CVE-2026-67409 · 13d ago
CVE-2026-63498 — Snipe-IT is an IT asset/license management system.
CVE-2026-63498 · 14d ago
CVE-2026-63493 — Snipe-IT is an IT asset/license management system.
CVE-2026-63493 · 14d ago