Two-Factor Authentication Vulnerability in Zammad Helpdesk System
CVE-2026-84461
6.9MEDIUM
What is CVE-2026-84461?
Zammad, an open-source helpdesk/customer support platform, has an authentication vulnerability that allows attackers to bypass normal account lockout mechanisms during the two-factor authentication process. Versions prior to 7.1.2 permit unlimited password guessing attempts, enabling potential brute-force attacks against weak or reused passwords. Importantly, the system inadvertently informs attackers whether a guessed password is correct, even before the two-factor authentication is validated. This flaw could compromise user account security significantly until rectified in version 7.1.2.
Affected Version(s)
zammad < 7.1.2
