PT-2026-89039 · Git+1 · Snipe-It

·

CVE-2026-86770

·

Publicado

2026-09-09

·

Atualizado

2026-09-09

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4 unicode ci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-86770
GHSA-W3VV-5WXH-XG4H

Produtos afetados

Snipe-It