CVE-2026-86770
Undergoing Analysis Undergoing Analysis - In Progress

Snipe-IT Authentication Bypass via SAML Username Case Sensitivity

Vulnerability report for CVE-2026-86770, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4_unicode_ci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)
grokability snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-178 The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Snipe-IT before version 8.7.0 has a vulnerability where it fails to validate username case sensitivity during SAML authentication. Attackers can register Identity Provider accounts with accent or case variants of victim usernames, exploiting the default utf8mb4_unicode_ci database collation to bypass username matching and gain unauthorized access.

Detection Guidance

Check Snipe-IT version with: grep -r "version" /path/to/snipe-it/config/app.php. If version is below 8.7.0, the system is vulnerable. Inspect database collation for users.username column with: SELECT TABLE_NAME, COLUMN_NAME, COLLATION_NAME FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_SCHEMA = 'your_database' AND COLUMN_NAME = 'username' AND TABLE_NAME = 'users';

Review authentication logs for SAML/LDAP/OAuth login attempts with unusual case or accented usernames. Look for patterns like 'snΓ­peitreport3' vs 'snipeitreport3' in access logs.

Impact Analysis

An attacker could exploit this to log in as another user without credentials, potentially accessing sensitive data or performing unauthorized actions. The attack requires minimal privileges, no victim interaction, and works across SAML, LDAP, and OAuth login paths.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, which may violate compliance requirements under GDPR (e.g., unauthorized data access under Article 32) and HIPAA (e.g., unauthorized access to protected health information under the Security Rule). The lack of proper username validation during authentication undermines security controls required by these regulations.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. If upgrading is not possible, apply the patch from commit 2304066d79 which adds the verifyExactUsernameMatch filter to prevent collation bypass.

Temporarily disable federated login paths (SAML, LDAP, OAuth) until patched. Review and remove any IdP accounts with case or accent variants of existing usernames.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86770. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart