Executive brief
Zammad is an open-source customer support and helpdesk platform. A security flaw in its Single Sign-On (SSO) system could allow an attacker to bypass certain identity checks because the software does not verify if login information is coming from a trusted source. This could potentially lead to unauthorized access to support tickets or customer data.
Technical details
An origin validation error (CWE-346) exists in the SSO mechanism of Zammad. The application fails to verify that incoming SSO headers originate from a trusted proxy or gateway before processing them. An attacker with network access and low-level privileges could potentially exploit this lack of verification to manipulate session data or gain unauthorized access. The vulnerability is addressed in versions 7.0.1 and 6.5.4 by allowing administrators to properly configure trusted sources for SSO headers.
Affected products
- Zammad Zammad < 6.5.4, >= 7.0.0-alpha, < 7.0.1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched