CVE-2026-86756
CVE-2026-86756 is a medium-severity vulnerability in Snipeitapp Snipe-it with a CVSS 3.x base score of 6.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-601.
Key facts
- Severity: Medium (CVSS 3.x base score 6.1)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-601
- Affected product: Snipeitapp Snipe-it
- Published:
- Last modified:
Description
Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.
Frequently asked questions
- What is CVE-2026-86756?
- Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.
- How severe is CVE-2026-86756?
- CVE-2026-86756 has a CVSS 3.x base score of 6.1, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-86756 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-86756?
- CVE-2026-86756 affects Snipeitapp Snipe-it. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-86756?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-86756 published?
- CVE-2026-86756 was published on 2026-09-09 and last updated on 2026-09-16.
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-68hq-m589-8q9j
- https://www.vulncheck.com/advisories/snipe-it-8.5.0-through-8.6.3-open-redirect-via-saml-relaystate
Affected products (1)
- cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
More vulnerabilities in Snipeitapp Snipe-it
- CVE-2025-63601 — Critical (CVSS 9.9): Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to…
- CVE-2026-37709 — Critical (CVSS 9.8): Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit…
- CVE-2026-85617 — High (CVSS 8.8): snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that…
- CVE-2026-55643 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can…
- CVE-2026-55483 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission…
- CVE-2026-44832 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit…
All CVEs affecting Snipeitapp Snipe-it →
Other CWE-601 (Open Redirect) vulnerabilities
- CVE-2018-3774 — Critical (CVSS 10.0): Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open…
- CVE-2026-101090 — Critical (CVSS 9.8): Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional…
- CVE-2019-25282 — Critical (CVSS 9.8): V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to…
- CVE-2020-36912 — Critical (CVSS 9.8): Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script…
- CVE-2025-43526 — Critical (CVSS 9.8): This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac…
- CVE-2025-55031 — Critical (CVSS 9.8): Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An…