CVE-2026-56733
Received Received - Intake

Authorization Bypass in Zammad Helpdesk System

Vulnerability report for CVE-2026-56733, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement of access restrictions during the initialization of new identity objects exhibits a discrepancy: Under specific conditions, the granular restrictions of the access key being used are overridden by the latent authorization authority of the parent account. Consequently, this means that the intended separation of functional areas is nullified, resulting in an uncontrolled expansion of administrative discretion. Due to this potential integrity breach of the entire trust environment, an immediate evaluation of the authorization hierarchies is imperative. Impact An attacker can create new administrator accounts despite token restrictions. This grants full access to all system data (tickets, customers, configuration) and allows the attacker to take complete control of the Zammad instance. Abuse Scenario The vulnerability stems from a lack of synergy between the token-based authorization logic and the target system's functional authorization hierarchy, which allows for iterative escalation of the privileged access context. This issue is fixed in versions 7.0.2 and 7.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zammad zammad to 7.0.2|end_excluding=7.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Zammad, a helpdesk system, allows attackers to create administrator accounts even when token restrictions should prevent it. The issue occurs because the system does not properly validate authorization during account creation, letting parent account permissions override token-based restrictions. This breaks the intended separation of access levels and grants full system control.

Impact Analysis

An attacker exploiting this flaw could gain full administrative access to your Zammad instance. This means they can view, modify, or delete all system data including tickets, customer information, and configurations. Essentially, they could take complete control of your helpdesk system and all its sensitive data.

Compliance Impact

This vulnerability could severely impact compliance with GDPR and HIPAA by enabling unauthorized access to sensitive personal data. GDPR requires strict access controls and data protection, while HIPAA mandates secure handling of protected health information. A breach through this vulnerability would likely violate these regulations, potentially resulting in legal penalties and loss of trust.

Mitigation Strategies

Immediately upgrade Zammad to version 7.0.2 or 7.1.0 or later to address the authorization bypass vulnerability. Review and audit all administrator accounts and authorization hierarchies to ensure proper access restrictions are in place.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56733. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart