External risk intelligence

Zammad Account Linking Vulnerability Allows Email Spoofing

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-84458

Zammad is a helpdesk and customer support system designed to be web-accessible for users and staff. As a web-based service providing ticket management and SSO integration, it is typically deployed as a public-facing application to facilitate communication and support requests from external users.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Zammad, a web-based customer support system. The issue allows an attacker to gain unauthorized access to accounts, including administrator privileges, by exploiting a flaw in how the system links external identity providers. This could lead to significant compromise of sensitive customer and operational data managed within Zammad.

  • Attackers can access accounts by impersonating users.
  • Leadership should remember this for potential customer support system risks.
  • Confirm Zammad relevance and assess exposure to sensitive data.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by controlling an identity within a configured third-party identity provider, such as Azure AD. By manipulating the email address associated with this controlled identity to match a victim's email, the attacker can then authenticate through Zammad's Single Sign-On (SSO) feature. If Zammad's "Automatic account link on initial logon" setting is enabled, the system will associate the authenticated third-party identity with an existing local Zammad account based on the email address, granting the attacker access to the victim's account without needing their password.

  • Attacker controls an identity provider.
  • Attacker authenticates via SSO.
  • Unauthorized account access.

Live Threat

Current exploitation, exposure, and threat context

When Zammad's "Automatic account link on initial logon" setting is enabled, an attacker can exploit a vulnerability to gain access to user accounts. This occurs when an attacker controls an identity at a configured provider, such as Azure AD, and sets that identity's email to a victim's address. By authenticating with this falsified identity, the attacker can log in as the victim, bypassing their local password and potentially accessing accounts with administrator privileges.

  • User accounts and agent/administrator access.
  • By linking a controlled identity to a victim's email.
  • Unauthorized access to sensitive support data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Zammad, a web-based helpdesk system, impacts systems where "Automatic account link on initial logon" is enabled. The primary responsibility likely falls on the Application or Platform team managing Zammad, with crucial involvement from the Network/Security team to assess external reachability and the Vendor Management team if a managed service is in use. The immediate first step is to identify all Zammad instances, determine their exposure and business criticality, and confirm the accountable owner to prioritize remediation efforts.

  • Application or Platform teams own the issue.
  • Verify Zammad instance reachability and criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zammad and why is it used?

Zammad is an open-source, web-based helpdesk and customer support platform. Organizations use it to centralize communication, manage ticket workflows, and facilitate customer service interactions. It integrates with various external systems to streamline user authentication, allowing support staff and customers to access the platform through common identity providers.

What is the weakness class behind CVE-2026-84458?

This vulnerability is classified as CWE-287, which refers to Improper Authentication. In this specific case, the flaw exists because the software incorrectly trusts the email address provided by an external authentication service. It fails to verify that the user actually owns that email address before linking the external login to an existing local account, allowing unauthorized access.

How does an attacker trigger this vulnerability?

An attacker must have control over an account at an identity provider that is configured to work with the target Zammad instance. By changing the email address on their controlled account to match a victim's email, they can perform an SSO login. The trigger requires the specific 'Automatic account link on initial logon' setting to be enabled. If this feature is disabled, the system does not automatically associate the accounts in this insecure manner.

Is my Zammad instance at risk?

If your instance uses SSO integrations and has 'Automatic account link on initial logon' enabled, it is potentially at risk. According to Halo Surface Signal, Zammad is frequently deployed as a public-facing web service to support external users. This network visibility often makes the authentication interface reachable to remote attackers, increasing the likelihood that they can attempt to leverage this flaw against your user or administrator accounts.

What should I do to secure my Zammad installation?

The most effective first step is to check if the 'Automatic account link on initial logon' setting is currently enabled in your Zammad configuration. If it is, consider disabling it until you can apply the official security update to version 7.1.2. Additionally, inventory your instances to identify which ones are internet-facing and prioritize them for patching or configuration changes to prevent unauthorized access.

References