CVE-2026-86756: Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState

Published Sep 9, 2026
·
Updated

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended session key with only CR/LF characters stripped, and LoginController later issued redirect()->intended(), which passes an absolute URL through to the Location header unchanged. An unauthenticated attacker who induces a user of a SAML-SSO-enabled instance to visit a crafted IdP-initiated SSO link can therefore cause the victim's browser to be redirected to an arbitrary absolute external URL immediately after a successful authentication, which the advisory notes facilitates credential-harvesting phishing. No account on the target instance and no compromise of the identity provider are required. Only deployments with SAML SSO enabled are affected. Fixed in 8.7.0 (commit d30b73d, PR #19386), which validates RelayState via a new Helper::sameOriginUrl check before storing it.

Affected Software

1 affected component
Snipe-IT Snipe-IT>=8.5.0<=8.6.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Fixed in 8.7.0Patch d30b73d
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch PR #19386

Event History

Sep 9, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Only Snipe-IT deployments with SAML SSO enabled are affected. The issue applies to versions 8.5.0 through 8.6.3.

2

What must an attacker do to exploit this issue?

An attacker must induce a user of an affected instance to visit a crafted IdP-initiated SSO link. No account on the Snipe-IT instance and no compromise of the identity provider are required.

3

What is the practical impact on users?

After the user successfully authenticates through SAML, their browser can be redirected to an arbitrary external URL. The advisory notes that this can facilitate credential-harvesting phishing.

4

How can the issue be remediated?

Upgrade to Snipe-IT 8.7.0. The fix validates RelayState with a same-origin URL check before it is stored for the post-login redirect.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203