PT-2026-98947 · Zammad · Zammad

CVE-2026-56733

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.2 Zammad versions prior to 7.1.0
Description Zammad is a web-based open source helpdesk and customer support system. The issue involves a lack of discursive validation within the authorization cascade, where system-level enforcement of access restrictions during the initialization of new identity objects is inconsistent. Under specific conditions, the granular restrictions of an access key are overridden by the latent authorization authority of the parent account, nullifying the separation of functional areas and expanding administrative discretion. This allows an attacker to bypass token restrictions to create new administrator accounts, granting full access to system data, including tickets, customers, and configuration, leading to complete control of the instance. The flaw arises from a lack of synergy between token-based authorization logic and the functional authorization hierarchy, enabling iterative escalation of the privileged access context.
Recommendations Update to version 7.0.2. Update to version 7.1.0.

Exploit

Fix

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56733
GHSA-P3MG-2JXR-HWW2

Affected Products

Zammad