Vulnerability in Zammad Helpdesk Software Exposes Internal Network
CVE-2026-56734
What is CVE-2026-56734?
Zammad, an open-source helpdesk/customer support system, has a vulnerability related to federated authentication methods such as OAuth, OIDC, and SAML. In versions prior to 7.0.2, the application retrieves a profile image URL from an external identity provider without validating the target address. This flaw can be exploited by an actor who can modify their profile image URL on the connected provider, potentially leading the server to connect to internal network locations. The differential response patterns between reachable and unreachable targets may allow attackers to probe internal services. Additionally, affected worker processes could experience blocking for several seconds per request. This issue was resolved in version 7.0.2.
Affected Version(s)
zammad < 7.0.2
