Authentication Bypass in Zammad Affects User Sessions
CVE-2020-26030
9.8CRITICAL
What is CVE-2020-26030?
A serious vulnerability exists in Zammad software versions prior to 3.4.1, allowing attackers to bypass authentication through a crafted header in the SSO endpoint when SSO is not properly configured. This flaw enables an attacker to establish a valid, authenticated session and execute actions on behalf of other users, potentially compromising user data and system integrity.
