CVE-2026-84464: Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization data

Published Sep 25, 2026
·
Updated

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specific ticket, user, group, or organization before including its details in a request to that external system. An authenticated user, including one with only basic customer access, could exploit this by referencing another record's ID, and thereby view details of tickets, customer accounts, teams, or organizations that did not belong to them. This issue is fixed in version 7.1.2.

Affected Software

1 affected component
Zammad Zammad<7.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Zammad to a version that resolves this vulnerability.

    Fixed in 7.1.2

Event History

Sep 25, 2026
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Zammad user can potentially exploit it, including users with only basic customer access. The user would need to reference the ID of a ticket, user, group, or organization they are not authorized to view.

2

Which data may be exposed?

The affected External Data Source rendering can expose details of tickets, customer accounts, teams, and organizations belonging to other users or groups.

3

Are installations affected by default?

The issue is in Zammad's External Data Source feature. The provided information does not state whether that feature is enabled or configured by default.

4

What version fixes the issue?

Upgrade Zammad to version 7.1.2 or later. Versions prior to 7.1.2 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203