Identity Binding Vulnerability in Zammad Helpdesk System
CVE-2026-84458

9.1CRITICAL

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-84458?

The Zammad helpdesk system allows for a significant security risk due to improper email verification during the automatic account linking process. When the 'Automatic account link on initial logon' feature is enabled, Zammad binds external identities from identity providers, such as Azure AD, to existing local accounts solely based on matching email addresses. An attacker could exploit this flaw by controlling an identity at a configured provider, allowing them to log in as any victim whose email address has not been verified. This issue could lead to unauthorized access, affecting all account types, including agents and administrators. The issue has been resolved in version 7.1.2.

Affected Version(s)

zammad < 7.1.2

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.