Description
Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect enabling credential‑harvesting phishing
Action: Patch
AI Analysis

Impact

Snipe‑IT 8.5.0 through 8.6.3 contains an open redirect in the SAML assertion‑consumer endpoint. The vulnerability allows an attacker to embed an arbitrary absolute URL in the RelayState parameter, which is then passed unchanged to the HTTP Location header after successful authentication. Because no account or IdP compromise is required, this flaw can be exploited by an unauthenticated attacker who supplies a crafted IdP‑initiated SSO link to a victim. The resulting redirect can lead the victim to phishing sites designed to harvest credentials.

Affected Systems

The flaw affects Snipe‑IT instances that have SAML SSO enabled. The affected range is version 8.5.0 through 8.6.3. Higher‑level vendor is Grokability. The patch is available in 8.7.0 (commit d30b73d).

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attack execution requires only an SSO link with a crafted RelayState; it does not require prior authentication or IdP compromise, so the likelihood of attack is high for exposed SAML SSO endpoints.

Generated by OpenCVE AI on September 9, 2026 at 15:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later, which validates RelayState with a same‑origin check.
  • If upgrading is not immediately possible, disable SAML SSO on affected instances to eliminate the redirect path.
  • As a temporary measure, manually review the SAML configuration to ensure the RelayState parameter is not passed directly into the redirect and that only same‑origin URLs are permitted; at minimum, filter the RelayState input to allow only relative paths or URLs matching the instance host.

Generated by OpenCVE AI on September 9, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.
Title Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-601
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:22:16.757Z

Reserved: 2026-09-08T11:32:11.096Z

Link: CVE-2026-86756

cve-icon Vulnrichment

Updated: 2026-09-09T14:22:14.192Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:24.883

Modified: 2026-09-16T20:25:23.380

Link: CVE-2026-86756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:15:06Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')