CVE-2026-84464: Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization data
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specific ticket, user, group, or organization before including its details in a request to that external system. An authenticated user, including one with only basic customer access, could exploit this by referencing another record's ID, and thereby view details of tickets, customer accounts, teams, or organizations that did not belong to them. This issue is fixed in version 7.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.1.2
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated Zammad user can potentially exploit it, including users with only basic customer access. The user would need to reference the ID of a ticket, user, group, or organization they are not authorized to view.
Which data may be exposed?
The affected External Data Source rendering can expose details of tickets, customer accounts, teams, and organizations belonging to other users or groups.
Are installations affected by default?
The issue is in Zammad's External Data Source feature. The provided information does not state whether that feature is enabled or configured by default.
What version fixes the issue?
Upgrade Zammad to version 7.1.2 or later. Versions prior to 7.1.2 are affected.