PT-2026-98947 · Zammad · Zammad
CVE-2026-56733
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.0.2
Zammad versions prior to 7.1.0
Description
Zammad is a web-based open source helpdesk and customer support system. The issue involves a lack of discursive validation within the authorization cascade, where system-level enforcement of access restrictions during the initialization of new identity objects is inconsistent. Under specific conditions, the granular restrictions of an access key are overridden by the latent authorization authority of the parent account, nullifying the separation of functional areas and expanding administrative discretion. This allows an attacker to bypass token restrictions to create new administrator accounts, granting full access to system data, including tickets, customers, and configuration, leading to complete control of the instance. The flaw arises from a lack of synergy between token-based authorization logic and the functional authorization hierarchy, enabling iterative escalation of the privileged access context.
Recommendations
Update to version 7.0.2.
Update to version 7.1.0.
Exploit
Fix
Incorrect Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad