PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86756 grokability CVE debrief

CVE-2026-86756 is an open redirect vulnerability in Snipe-IT versions 8.5.0 through 8.6.3. The vulnerability exists in the SAML assertion-consumer endpoint and allows an unauthenticated attacker to redirect a user's browser to an arbitrary external URL after a successful authentication. This facilitates credential-harvesting phishing. Only deployments with SAML SSO enabled are affected. The issue was fixed in version 8.7.0.

Vendor
grokability
Product
snipe-it
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-16
Advisory published
2026-09-09
Advisory updated
2026-09-16

Who should care

Defenders of Snipe-IT instances with SAML SSO enabled should assess exposure and prioritize upgrading to version 8.7.0 or later. This involves verifying instance configurations, reviewing security settings, and ensuring that SAML SSO is properly configured. Additionally, defenders should educate users on phishing risks and monitor for suspicious activity.

Why it matters

CVE-2026-86756 is an open redirect vulnerability in Snipe-IT that allows attackers to redirect users to arbitrary external URLs after authentication, facilitating phishing attacks. Defenders of Snipe-IT instances with SAML SSO enabled should verify exposure and prioritize upgrading to version 8.7.0 or later.

  • Credential harvesting through phishing
  • Potential for unauthorized access
  • Increased risk of account compromise
  • Need for verification of instance exposure

Technical summary

The vulnerability exists in the SAML assertion-consumer endpoint of Snipe-IT versions 8.5.0 through 8.6.3. An unauthenticated attacker can cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication by inducing the user to visit a crafted IdP-initiated SSO link. This issue allows for credential-harvesting phishing attacks. The vulnerability was fixed in version 8.7.0, which validates RelayState via a new Helper::sameOriginUrl check before storing it.

Defensive priority

Defenders should prioritize verifying exposure of SAML-SSO-enabled Snipe-IT instances and upgrading to version 8.7.0 or later.

Recommended defensive actions

  • Verify if SAML-SSO is enabled on Snipe-IT instances
  • Upgrade to Snipe-IT version 8.7.0 or later
  • Monitor for suspicious redirect activity
  • Educate users on phishing risks
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed version. Vendor advisory and third-party advisory references are also available. The vulnerability was introduced in Snipe-IT versions 8.5.0 through 8.6.3 and fixed in version 8.7.0. Limited evidence suggests that deployments with SAML SSO enabled are affected. Defenders should verify instance exposure and review official advisories for further details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86756 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86756

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86756 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86756

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-68hq-m589-8q9j

    [email protected] - Exploit, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/snipe-it-8.5.0-through-8.6.3-open-redirect-via-saml-relaystate

    [email protected] - Third Party Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.