Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Zammad, a web-based customer support system. The issue allows an attacker to gain unauthorized access to accounts, including administrator privileges, by exploiting a flaw in how the system links external identity providers. This could lead to significant compromise of sensitive customer and operational data managed within Zammad.
- Attackers can access accounts by impersonating users.
- Leadership should remember this for potential customer support system risks.
- Confirm Zammad relevance and assess exposure to sensitive data.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by controlling an identity within a configured third-party identity provider, such as Azure AD. By manipulating the email address associated with this controlled identity to match a victim's email, the attacker can then authenticate through Zammad's Single Sign-On (SSO) feature. If Zammad's "Automatic account link on initial logon" setting is enabled, the system will associate the authenticated third-party identity with an existing local Zammad account based on the email address, granting the attacker access to the victim's account without needing their password.
- Attacker controls an identity provider.
- Attacker authenticates via SSO.
- Unauthorized account access.
Live Threat
Current exploitation, exposure, and threat context
When Zammad's "Automatic account link on initial logon" setting is enabled, an attacker can exploit a vulnerability to gain access to user accounts. This occurs when an attacker controls an identity at a configured provider, such as Azure AD, and sets that identity's email to a victim's address. By authenticating with this falsified identity, the attacker can log in as the victim, bypassing their local password and potentially accessing accounts with administrator privileges.
- User accounts and agent/administrator access.
- By linking a controlled identity to a victim's email.
- Unauthorized access to sensitive support data.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Zammad, a web-based helpdesk system, impacts systems where "Automatic account link on initial logon" is enabled. The primary responsibility likely falls on the Application or Platform team managing Zammad, with crucial involvement from the Network/Security team to assess external reachability and the Vendor Management team if a managed service is in use. The immediate first step is to identify all Zammad instances, determine their exposure and business criticality, and confirm the accountable owner to prioritize remediation efforts.
- Application or Platform teams own the issue.
- Verify Zammad instance reachability and criticality.
- Plan remediation based on confirmed risk.