PT-2026-89039 · Git+1 · Snipe-It

·

CVE-2026-86770

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4 unicode ci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86770
GHSA-W3VV-5WXH-XG4H

Affected Products

Snipe-It