Single Sign-On Header Verification Flaw in Zammad Helpdesk System
CVE-2026-34720

2.3LOW

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-34720?

In Zammad, a popular open source helpdesk and customer support system, a vulnerability exists in the Single Sign-On (SSO) mechanism. This flaw allows the SSO system to process headers without verifying that they originate from a trusted proxy or gateway, potentially enabling unauthorized actions. This issue has been addressed in versions 7.0.1 and 6.5.4, which implement strict verification methods to enhance the security of the SSO process.

Affected Version(s)

zammad < 6.5.4 < 6.5.4

zammad >= 7.0.0-alpha, < 7.0.1 < 7.0.0-alpha, 7.0.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.