CVE-2026-84458
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity provider reports, without verifying that the provider actually confirmed ownership of that email. An attacker who controls any identity at a configured provider, including, by default, any Azure AD tenant via Zammad's multi-tenant Microsoft 365 /common app registration, can set that identity's email to a victim's address, authenticate, and be logged in as the victim. This bypasses the victim's local password entirely and affects any existing account, including agents and administrators. Zammad will honor the xms_edov ID token claim when email verification is required in the Microsoft 365 setting, treating a missing claim as unverified. This issue is fixed in version 7.1.2.
Weaknesses
CWE-287
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2025-43936
- HIGHCVE-2026-100606PoC
- HIGHCVE-2026-100607PoC
- HIGHCVE-2026-100684PoC
- HIGHCVE-2026-100709PoC
- HIGHCVE-2026-100746PoC
- HIGHCVE-2026-100871PoC
- MEDIUMCVE-2026-100876PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.