OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-84458

CRITICAL · CVSS 9.1 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Zammad versions prior to 7.1.2 are vulnerable to a critical authentication bypass due to improper verification of email ownership during the automatic account linking process for third-party SSO logins. An attacker controlling an identity at a configured provider can exploit this flaw to impersonate any user, including agents and administrators, effectively bypassing local password protections. Organizations using Zammad for customer support should prioritize upgrading to version 7.1.2 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84458
Severity
CRITICAL
CVSS
9.1
EPSS
0.36%
Microsoft

Original NVD Description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity provider reports, without verifying that the provider actually confirmed ownership of that email. An attacker who controls any identity at a configured provider, including, by default, any Azure AD tenant via Zammad's multi-tenant Microsoft 365 /common app registration, can set that identity's email to a victim's address, authenticate, and be logged in as the victim. This bypasses the victim's local password entirely and affects any existing account, including agents and administrators. Zammad will honor the xms_edov ID token claim when email verification is required in the Microsoft 365 setting, treating a missing claim as unverified. This issue is fixed in version 7.1.2.