Executive brief
Snipe-IT is an asset and IT inventory management platform that supports federated login via SAML, LDAP, and OAuth. A vulnerability in username matching allows attackers to register accounts with accent or case variants of legitimate usernames (e.g., "snípeitreport3" instead of "snipeitreport3") and gain unauthorized access to victim accounts, potentially accessing or modifying sensitive asset records, configurations, and administrative functions.
Technical details
The vulnerability is an improper handling of case sensitivity (CWE-178) in the SAML authentication path. The vulnerable code queries the users table with a simple WHERE username = ? equality check; on MySQL/MariaDB with the default utf8mb4_unicode_ci collation, this lookup is both case-insensitive and accent-insensitive, allowing byte-distinct strings to match. An attacker with access to the identity provider (or on an IdP with self-registration) can create an account using an accent or case variant of a victim's username; the SAML login resolves this to the victim's local account and authenticates the attacker's session as that user. The same bypass applies to LDAP and OAuth paths using identical query patterns. The fix, deployed in commit 2304066d79 on 2026-07-11 and released in version 8.7.0, enforces byte-exact username matching after the database query.
Affected products
- Snipe Snipe-IT before 8.7.0
Timeline
- 2026-09-09: disclosed: CVE-2026-86770 published
- 2026-07-11: patched: Fix committed to develop branch (commit 2304066d79)
- 2026-08-24: patched: GitHub Security Advisory GHSA-w3vv-5wxh-xg4h published; first tagged release with fix announced as 8.7.0