Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-86756
grokability snipe-it — Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N P L L N 5.3 .0033 24.2 —
AFFECTED
Product Versions Fixed
snipe-it 8.5.0 – —
TIMELINE
Sep 8 Reserved by VulnCheck
Sep 9 Published (CNA: VulnCheck)
Sep 16 EXPLOIT PUBLISHED — CVE-2026-86756 (grokability snipe-it). Public exploit reference added.
Description
Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 8, 2026 | Reserved | Reserved by VulnCheck |
| September 9, 2026 | Published | Published (CNA: VulnCheck) |
| September 16, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-86756 (grokability snipe-it). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| grokability | snipe-it | — | 8.5.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-86756 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.