CVE-2026-86770

Source
https://cve.org/CVERecord?id=CVE-2026-86770
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86770.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86770
Aliases
  • GHSA-w3vv-5wxh-xg4h
Published
2026-09-09T13:32:27Z
Modified
2026-09-10T03:48:29Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
Details

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4_unicode_ci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-178"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86770.json"
}
References

Affected packages

Git / github.com/grokability/snipe-it

Affected ranges

Type
GIT
Repo
https://github.com/grokability/snipe-it
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.6.3"
        },
        {
            "fixed": "8.7.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86770.json"