Impact
Snipe‑IT versions prior to 8.7.0 allow an attacker to bypass authentication because the application does not enforce case sensitivity on usernames during SAML, LDAP, and OAuth authentication. By creating IdP accounts that use accent or case variants of a target user’s name, an attacker can log in as that user. This results in account takeover and full compromise of the victim account. The weakness is a case‑sensitivity validation defect (CWE‑178).
Affected Systems
All Snipe‑IT installations of version 8.6.x or earlier, including any build before the 8.7.0 release, are affected. The flaw exists in the core authentication module that handles federated login via SAML, LDAP, and OAuth and is present in the grokability Snipe‑IT product.
Risk and Exploitability
The CVSS score of 8.6 labels the issue as high severity. The EPSS score is not available, though the vulnerability is not listed in the CISA KEV catalog. Because the flaw is tied to user registration with variant usernames, an attacker only needs the ability to supply IdP credentials; once an IdP account is created, authentication succeeds without further input. The likely attack vector is a federated login path where the attacker registers a malicious IdP account that uses an alternate spelling of a target username. In the absence of mitigations, the vulnerability provides full account takeover.
OpenCVE Enrichment