PatchSiren cyber security CVE debrief
CVE-2026-86756 grokability CVE debrief
CVE-2026-86756 is an open redirect vulnerability in Snipe-IT versions 8.5.0 through 8.6.3. The vulnerability exists in the SAML assertion-consumer endpoint and allows an unauthenticated attacker to redirect a user's browser to an arbitrary external URL after a successful authentication. This facilitates credential-harvesting phishing. Only deployments with SAML SSO enabled are affected. The issue was fixed in version 8.7.0.
- Vendor
- grokability
- Product
- snipe-it
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-16
Who should care
Defenders of Snipe-IT instances with SAML SSO enabled should assess exposure and prioritize upgrading to version 8.7.0 or later. This involves verifying instance configurations, reviewing security settings, and ensuring that SAML SSO is properly configured. Additionally, defenders should educate users on phishing risks and monitor for suspicious activity.
Why it matters
CVE-2026-86756 is an open redirect vulnerability in Snipe-IT that allows attackers to redirect users to arbitrary external URLs after authentication, facilitating phishing attacks. Defenders of Snipe-IT instances with SAML SSO enabled should verify exposure and prioritize upgrading to version 8.7.0 or later.
- Credential harvesting through phishing
- Potential for unauthorized access
- Increased risk of account compromise
- Need for verification of instance exposure
Technical summary
The vulnerability exists in the SAML assertion-consumer endpoint of Snipe-IT versions 8.5.0 through 8.6.3. An unauthenticated attacker can cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication by inducing the user to visit a crafted IdP-initiated SSO link. This issue allows for credential-harvesting phishing attacks. The vulnerability was fixed in version 8.7.0, which validates RelayState via a new Helper::sameOriginUrl check before storing it.
Defensive priority
Defenders should prioritize verifying exposure of SAML-SSO-enabled Snipe-IT instances and upgrading to version 8.7.0 or later.
Recommended defensive actions
- Verify if SAML-SSO is enabled on Snipe-IT instances
- Upgrade to Snipe-IT version 8.7.0 or later
- Monitor for suspicious redirect activity
- Educate users on phishing risks
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed version. Vendor advisory and third-party advisory references are also available. The vulnerability was introduced in Snipe-IT versions 8.5.0 through 8.6.3 and fixed in version 8.7.0. Limited evidence suggests that deployments with SAML SSO enabled are affected. Defenders should verify instance exposure and review official advisories for further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86756 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86756
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86756 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86756
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-68hq-m589-8q9j
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/snipe-it-8.5.0-through-8.6.3-open-redirect-via-saml-relaystate
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.