---
id: CVE-2026-86770
title: >-
  Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML
  authentication, allowing attackers to authenticate as different users by
  registering IdP accounts with accent or case variants of victim usernames
summary: >-
  Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML
  authentication, allowing attackers to authenticate as different users by
  registering IdP accounts with accent or case variants of victim usernames.
  Attackers c…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-178
vendor: snipeitapp
product: snipe-it
affected:
  - snipe-it < 8.7.0
patched:
  - snipe-it 8.7.0
published: '2026-09-09'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:28:43.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86770'
references:
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-w3vv-5wxh-xg4h
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-authentication-bypass-via-saml-username-collation
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-w3vv-5wxh-xg4h
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00571
epssPercentile: 0.4501
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T13:31:28.501680Z'
ingestedAt: '2026-09-14T15:23:07.419Z'
---

## Overview

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4_unicode_ci database collation to bypass username matching and achieve account takeover through federated login paths including SAML, LDAP, and OAuth.

## Affected

- `snipe-it < 8.7.0`

## Remediation

Upgrade past the affected range:

- `snipe-it 8.7.0`
