CVE-2026-34721: Zammad has Cross-site request forgery (CSRF) in OAuth callback endpoints
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 6.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34721?
CVE-2026-34721 is classified as a high-severity vulnerability due to its potential impact on user authentication.
How do I fix CVE-2026-34721?
To fix CVE-2026-34721, update Zammad to version 7.0.1 or 6.5.4 or later.
What type of vulnerability is CVE-2026-34721?
CVE-2026-34721 is a Cross-site request forgery (CSRF) vulnerability impacting OAuth callback endpoints.
Which versions of Zammad are affected by CVE-2026-34721?
CVE-2026-34721 affects Zammad versions prior to 7.0.1 and 6.5.4.
What external services are impacted by CVE-2026-34721?
CVE-2026-34721 impacts the OAuth callback endpoints for Microsoft, Google, and Facebook within Zammad.