Identity Binding Vulnerability in Zammad Helpdesk System
CVE-2026-84458
9.1CRITICAL
What is CVE-2026-84458?
The Zammad helpdesk system allows for a significant security risk due to improper email verification during the automatic account linking process. When the 'Automatic account link on initial logon' feature is enabled, Zammad binds external identities from identity providers, such as Azure AD, to existing local accounts solely based on matching email addresses. An attacker could exploit this flaw by controlling an identity at a configured provider, allowing them to log in as any victim whose email address has not been verified. This issue could lead to unauthorized access, affecting all account types, including agents and administrators. The issue has been resolved in version 7.1.2.
Affected Version(s)
zammad < 7.1.2
