PT-2026-98948 · Zammad · Zammad
CVE-2026-56734
·
Published
2026-09-25
·
Updated
2026-09-29
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.0.2
Description
During federated authentication (OAuth, OIDC, or SAML), the system fetches a profile image URL from an external identity provider without verifying the target address. An actor with control over their profile at a connected provider can force the server to connect to internal network locations. This allows for internal service probing by analyzing differences in response timing and error patterns between reachable and unreachable targets. Additionally, worker processes may be blocked for several seconds per request.
Recommendations
Update to version 7.0.2.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad