CVE-2026-84458
Received Received - Intake

Incorrect Email Binding in Zammad via SSO Identity Spoofing

Vulnerability report for CVE-2026-84458, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity provider reports, without verifying that the provider actually confirmed ownership of that email. An attacker who controls any identity at a configured provider, including, by default, any Azure AD tenant via Zammad's multi-tenant Microsoft 365 /common app registration, can set that identity's email to a victim's address, authenticate, and be logged in as the victim. This bypasses the victim's local password entirely and affects any existing account, including agents and administrators. Zammad will honor the xms_edov ID token claim when email verification is required in the Microsoft 365 setting, treating a missing claim as unverified. This issue is fixed in version 7.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zammad zammad 7.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zammad is a helpdesk system vulnerable prior to version 7.1.2. When the 'Automatic account link on initial logon' setting is enabled, Zammad links a third-party identity to an existing local account by matching the email address reported by the identity provider without verifying ownership. An attacker controlling any identity at a configured provider, including Azure AD tenants, can set the email to a victim's address, authenticate, and gain access to the victim's account without needing the local password.

Detection Guidance

To detect this vulnerability, check if your Zammad instance is running a version prior to 7.1.2. Review the 'Automatic account link on initial logon' setting and verify if third-party identity providers are properly validating email ownership. Inspect authentication logs for suspicious logins where email addresses were matched without verification.

Impact Analysis

This vulnerability allows attackers to impersonate any user, including administrators, by exploiting weak email matching in SSO authentication. It bypasses local password requirements and could lead to unauthorized access to sensitive data, system manipulation, or privilege escalation within the Zammad helpdesk system.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's access controls. It undermines security measures required for compliance, potentially resulting in data breaches and regulatory penalties due to inadequate authentication safeguards.

Mitigation Strategies

Upgrade Zammad to version 7.1.2 or later to address the vulnerability. Disable the 'Automatic account link on initial logon' setting if it is enabled. Review and restrict identity provider configurations, especially for multi-tenant setups like Azure AD.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84458. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart