PT-2026-99085 · Zammad · Zammad

CVE-2026-84458

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description When the "Automatic account link on initial logon" setting is enabled, the system binds an incoming third-party Single Sign-On (SSO) identity to an existing local account by matching the reported email address without verifying that the provider confirmed ownership of that email. An attacker controlling an identity at a configured provider, such as any Azure AD tenant via the multi-tenant Microsoft 365 /common app registration, can set their identity email to a victim's address to authenticate and gain access to the victim's account. This allows the bypass of local passwords for any account, including agents and administrators. In the Microsoft 365 setting, the system honors the xms edov ID token claim for email verification, treating a missing claim as unverified.
Recommendations Update to version 7.1.2. Disable the "Automatic account link on initial logon" setting as a temporary mitigation measure.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84458
GHSA-86CC-3GGH-MF2M

Affected Products

Zammad