PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-56734 zammad CVE debrief

CVE-2026-56734 is a vulnerability in Zammad, a web-based open-source helpdesk/customer support system. Prior to version 7.0.2, during federated authentication, a profile image URL from an external identity provider is fetched without verifying the target address. This allows an actor who controls their profile at a connected provider to cause the server to connect to internal network locations, enabling internal service probing through response timing and error patterns. Worker processes may be blocked for several seconds per request. The issue requires a configured external authentication provider where the actor can modify their profile image URL and is fixed in version 7.0.2.

Vendor
zammad
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Zammad deployments, especially those using federated authentication with external providers, should assess their exposure to internal network locations and prioritize upgrading to Zammad version 7.0.2 or later.

Why it matters

Defenders should care about CVE-2026-56734 because it allows internal service probing and potential worker process delays in Zammad deployments using federated authentication. The vulnerability requires verification of exposure and prioritization of remediation through upgrading to version 7.0.2 or later.

  • Internal service probing through response timing and error patterns
  • Worker processes may be blocked for several seconds per request
  • Potential for unauthorized internal network location discovery

Technical summary

The vulnerability in Zammad allows an actor with control over their profile at a connected external authentication provider to cause the server to connect to internal network locations. This is achieved by fetching a profile image URL without verifying the target address, enabling internal service probing through response timing and error patterns. The issue requires a configured external authentication provider where the actor can modify their profile image URL.

Defensive priority

Defenders should prioritize verifying exposure to internal network locations and upgrading to Zammad version 7.0.2 or later. They should also assess their current authentication provider configurations and monitor for unusual activity.

Recommended defensive actions

  • Verify current Zammad version and upgrade to 7.0.2 or later if necessary
  • Assess external authentication provider configurations for potential exposure
  • Monitor worker process performance for unusual delays
  • Review internal network locations for potential probing attempts
  • Perform vulnerability scanning to identify exposed deployments
  • Implement additional logging to detect potential exploitation attempts
  • Review incident response plans for potential CVE-2026-56734 exploitation

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, its impact, and the fix in version 7.0.2. However, additional information about affected deployments and exploitation attempts is not available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-56734 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-56734

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-56734 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56734

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.