CVE-2026-86770: Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

Published Sep 9, 2026
·
Updated

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4unicodeci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.

Affected Software

1 affected component
Snipe-IT Snipe-IT<8.7.0

Event History

Sep 9, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Snipe-IT deployments before 8.7.0 that use federated authentication paths are exposed, including SAML, LDAP, and OAuth. The described bypass relies on the default utf8mb4_unicode_ci database collation.

2

What does an attacker need to exploit it?

An attacker needs an identity-provider account whose username is an accent or case variant of a victim's username. They also need access to a federated login path accepted by the affected Snipe-IT deployment.

3

What is the likely impact of successful exploitation?

Successful exploitation allows authentication as a different user and can result in account takeover. The affected matching behavior can cause the variant username to be treated as the victim's username.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203