boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-86756

grokability snipe-it — Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   L   N    5.3   .0033   24.2     —
AFFECTED
  Product   Versions  Fixed
  snipe-it  8.5.0 –   —
TIMELINE
  Sep 8   Reserved by VulnCheck
  Sep 9   Published (CNA: VulnCheck)
  Sep 16  EXPLOIT PUBLISHED — CVE-2026-86756 (grokability snipe-it). Public exploit reference added.
CWE-601 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed

Description

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 8, 2026ReservedReserved by VulnCheck
September 9, 2026PublishedPublished (CNA: VulnCheck)
September 16, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-86756 (grokability snipe-it). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
grokabilitysnipe-it—8.5.0—

Weaknesses

CWE-601

References (2)

Related

Authoritative record: CVE-2026-86756 at cve.org

Vendors: grokability

Weaknesses: CWE-601

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-86756 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.