CVE-2026-86756 | Grokability Snipe-IT 8.5.0/8.6.3 Saml Controller /saml/acs SamlController::acs RelayState redirect (d30b73d/19386)
A vulnerability categorized as problematic has been discovered in Grokability Snipe-IT 8.5.0/8.6.3. Affected is the function SamlController::acs of the file /saml/acs of the component Saml Controller. Executing a manipulation of the argument RelayState can lead to open redirect.
This vulnerability is tracked as CVE-2026-86756. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More