PT-2026-98948 · Zammad · Zammad

CVE-2026-56734

·

Published

2026-09-25

·

Updated

2026-09-29

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.2
Description During federated authentication (OAuth, OIDC, or SAML), the system fetches a profile image URL from an external identity provider without verifying the target address. An actor with control over their profile at a connected provider can force the server to connect to internal network locations. This allows for internal service probing by analyzing differences in response timing and error patterns between reachable and unreachable targets. Additionally, worker processes may be blocked for several seconds per request.
Recommendations Update to version 7.0.2.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56734
GHSA-Q3CR-3WQ3-29HX

Affected Products

Zammad