Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-84458: Zammad lets attacker log in as any user

CVE-2026-84458 · published 15 days ago
Summary

If Zammad’s automatic account linking for single sign‑on is turned on, it can link a new login to an existing account just by matching the email address, without checking that the email really belongs to the user. An attacker who can create or control an account with the identity provider can set that account’s email to someone else’s address and gain access to the victim’s Zammad account, including admin accounts, without needing the victim’s password. Upgrade to Zammad version 7.1.2 or later, or disable the automatic account linking feature, to stop this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
zammad zammad < 7.1.2
Original advisory text
Zammad: Account takeover via unverified email matching during SSO auto-link
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity provider reports, without verifying that the provider actually confirmed ownership of that email. An attacker who controls any identity at a configured provider, including, by default, any Azure AD tenant via Zammad's multi-tenant Microsoft 365 /common app registration, can set that identity's email to a victim's address, authenticate, and be logged in as the victim. This bypasses the victim's local password entirely and affects any existing account, including agents and administrators. Zammad will honor the xms_edov ID token claim when email verification is required in the Microsoft 365 setting, treating a missing claim as unverified. This issue is fixed in version 7.1.2.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-287Improper Authentication
Timeline
Published25 Sep 2026
Updated9 Oct 2026
First seen25 Sep 2026
Sources
CVE-2026-84458 · MITRE
Track software like this
Free during beta