Description
Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4_unicode_ci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.
Published: 2026-09-09
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via authentication bypass
Action: Immediate Patch
AI Analysis

Impact

Snipe‑IT versions prior to 8.7.0 allow an attacker to bypass authentication because the application does not enforce case sensitivity on usernames during SAML, LDAP, and OAuth authentication. By creating IdP accounts that use accent or case variants of a target user’s name, an attacker can log in as that user. This results in account takeover and full compromise of the victim account. The weakness is a case‑sensitivity validation defect (CWE‑178).

Affected Systems

All Snipe‑IT installations of version 8.6.x or earlier, including any build before the 8.7.0 release, are affected. The flaw exists in the core authentication module that handles federated login via SAML, LDAP, and OAuth and is present in the grokability Snipe‑IT product.

Risk and Exploitability

The CVSS score of 8.6 labels the issue as high severity. The EPSS score is not available, though the vulnerability is not listed in the CISA KEV catalog. Because the flaw is tied to user registration with variant usernames, an attacker only needs the ability to supply IdP credentials; once an IdP account is created, authentication succeeds without further input. The likely attack vector is a federated login path where the attacker registers a malicious IdP account that uses an alternate spelling of a target username. In the absence of mitigations, the vulnerability provides full account takeover.

Generated by OpenCVE AI on September 9, 2026 at 15:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later to enforce case‑sensitive username comparison.
  • Temporarily disable SAML, LDAP, and OAuth authentication until the upgrade can be performed, or restrict IdP account creation to trusted services.
  • Reconfigure the database to use a case‑sensitive collation such as utf8mb4_bin and enforce server‑side username validation to reject case or accent variations.

Generated by OpenCVE AI on September 9, 2026 at 15:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4_unicode_ci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.
Title Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-178
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:31:53.352Z

Reserved: 2026-09-08T11:35:02.617Z

Link: CVE-2026-86770

cve-icon Vulnrichment

Updated: 2026-09-14T13:31:46.299Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:27.593

Modified: 2026-09-16T20:28:43.957

Link: CVE-2026-86770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:15:06Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity