Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zammad was not verifying the header originates from a trusted SSO proxy/gateway before applying further actions on it. This vulnerability is fixed in 7.0.1 and 6.5.4.
CVSS
No CVSS.
References
Configurations
No configuration.
History
08 Apr 2026, 19:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-08 19:25
Updated : 2026-04-08 21:26
NVD link : CVE-2026-34720
Mitre link : CVE-2026-34720
CVE.ORG link : CVE-2026-34720
JSON object : View
Products Affected
No product.
CWE
CWE-346
Origin Validation Error
