CVE-2026-56734: Zammad: Avatar Image URL Server-Side Request Forwarding

Published Sep 25, 2026
·
Updated

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target address. An actor who controls their profile at a connected provider may cause the server to connect to internal network locations. Response timing and error patterns differ between reachable and unreachable targets, allowing internal service probing. Worker processes may be blocked for several seconds per request. Requires a configured external authentication provider where the actor can modify their profile image URL. This issue is fixed in version 7.0.2.

Affected Software

1 affected component
Zammad Zammad<7.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Zammad to a version that resolves this vulnerability.

    Fixed in 7.0.2

Event History

Sep 25, 2026
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using a Zammad version prior to 7.0.2 with federated OAuth, OIDC, or SAML authentication configured are exposed when users of the connected identity provider can modify their profile image URL.

2

What does an attacker need to exploit this issue?

The attacker needs an account at a configured external identity provider and the ability to control that account's profile image URL. They can use that URL to cause the Zammad server to make requests to internal network locations.

3

What is the practical impact of exploitation?

Differences in response timing and errors for reachable versus unreachable targets can allow internal service probing. Requests can also block worker processes for several seconds each.

4

How can this be remediated?

Upgrade Zammad to version 7.0.2, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203