CVE-2020-26030: Critical severity zammad vulnerability
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Zammad?
The vulnerability ID for this issue in Zammad is CVE-2020-26030.
What is the severity of CVE-2020-26030?
The severity of CVE-2020-26030 is critical with a CVSS score of 9.8.
How does the authentication bypass in the SSO endpoint work?
The authentication bypass in the SSO endpoint occurs when a crafted header is used, bypassing the authentication process when SSO is not configured.
Which versions of Zammad are affected by CVE-2020-26030?
Zammad versions from 1.0.0 to 3.4.1 are affected by CVE-2020-26030.
How can an attacker exploit CVE-2020-26030?
An attacker can exploit CVE-2020-26030 by creating a valid and authenticated session, allowing them to perform any actions in the name of other users.