CVE-2026-86756
Undergoing Analysis Undergoing Analysis - In Progress

Open Redirect in Snipe-IT via SAML RelayState

Vulnerability report for CVE-2026-86756, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it From 8.5.0 (inc) to 8.6.3 (inc)
snipe-it snipe-it 8.7.0
grokability snipe-it From 8.5.0 (inc) to 8.6.3 (inc)
grokability snipe-it 8.7.0
grokability snipe-it to 8.7.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86756 is an open redirect vulnerability in Snipe-IT versions 8.5.0 through 8.6.3. It occurs in the SAML assertion-consumer endpoint where the RelayState parameter is written directly into Laravel's url.intended session key after minimal sanitization. This allows an attacker to craft a malicious link that redirects a user to an arbitrary external URL immediately after successful authentication, enabling phishing attacks.

Detection Guidance

To detect this vulnerability, check if your Snipe-IT instance is running a vulnerable version (8.5.0 to 8.6.3) with SAML SSO enabled. Inspect the SAML assertion-consumer endpoint (POST /saml/acs) for improper RelayState handling. Look for direct writes to Laravel's url.intended session key without proper validation.

Impact Analysis

An attacker can trick a user into visiting a crafted link that triggers a SAML login. After authentication, the user is redirected to a malicious site controlled by the attacker, potentially stealing credentials or installing malware. No prior account access or identity provider compromise is needed.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by enabling phishing attacks that steal user credentials. GDPR requires protecting personal data, and HIPAA mandates safeguarding sensitive health information. A successful phishing attack exploiting this flaw could lead to unauthorized access to regulated data, potentially violating these standards.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later to apply the fix. Alternatively, disable SAML SSO in settings if upgrading is not feasible. Monitor network traffic for suspicious redirects or phishing attempts targeting SAML authentication flows.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86756. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart