CVE List

CVE-2020-26030

Severe 9.8

An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.

Published December 28, 2020.

Affected software

Get alerts for Zammad Zammad

Reference links