PT-2026-99085 · Zammad · Zammad
CVE-2026-84458
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
When the "Automatic account link on initial logon" setting is enabled, the system binds an incoming third-party Single Sign-On (SSO) identity to an existing local account by matching the reported email address without verifying that the provider confirmed ownership of that email. An attacker controlling an identity at a configured provider, such as any Azure AD tenant via the multi-tenant Microsoft 365
/common app registration, can set their identity email to a victim's address to authenticate and gain access to the victim's account. This allows the bypass of local passwords for any account, including agents and administrators. In the Microsoft 365 setting, the system honors the xms edov ID token claim for email verification, treating a missing claim as unverified.Recommendations
Update to version 7.1.2.
Disable the "Automatic account link on initial logon" setting as a temporary mitigation measure.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad