PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84458 zammad CVE debrief

CVE-2026-84458 is a critical vulnerability in Zammad, a web-based open-source helpdesk/customer support system. The issue allows an attacker to bind an incoming third-party identity to an existing local account by matching the email address reported by the identity provider, without verifying ownership of that email. This can lead to unauthorized access to accounts, including those of agents and administrators.

Vendor
zammad
Product
Unknown
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Zammad installations, especially those with the 'Automatic account link on initial logon' setting enabled, should assess their exposure and verify their configuration. They should also monitor for suspicious login attempts and review their identity provider's configuration.

Why it matters

CVE-2026-84458 is a critical vulnerability in Zammad that allows an attacker to gain unauthorized access to accounts by manipulating the email address reported by the identity provider. Defenders should prioritize verifying their Zammad installation's configuration and monitoring for suspicious login attempts.

  • Potential unauthorized access to accounts, including those of agents and administrators.
  • Bypassing of local password authentication.
  • Possible exploitation via identity provider manipulation.
  • Verification of email ownership and identity provider configuration required.

Technical summary

The vulnerability in Zammad allows an attacker to bind an incoming third-party identity to an existing local account by matching the email address reported by the identity provider, without verifying ownership of that email. This can lead to unauthorized access to accounts, including those of agents and administrators. The issue arises when the 'Automatic account link on initial logon' setting is enabled, and an attacker who controls any identity at a configured provider can set that identity's email to a victim's address, authenticate, and be logged in as the victim, bypassing the victim's local password entirely.

Defensive priority

Defenders should prioritize verifying their Zammad installation's configuration, especially the 'Automatic account link on initial logon' setting, and ensure that email verification is properly enforced. They should also monitor for any suspicious login attempts and review their identity provider's configuration.

Recommended defensive actions

  • Verify Zammad installation configuration, especially the 'Automatic account link on initial logon' setting.
  • Ensure email verification is properly enforced.
  • Monitor for suspicious login attempts.
  • Review identity provider configuration.
  • Perform vulnerability scanning to identify potentially exposed systems.
  • Implement additional logging and monitoring to detect potential exploitation attempts.
  • Review and update incident response plans to address potential exploitation of this vulnerability.

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, including its description, CVSS score, and affected versions. However, the corpus does not provide information on exploitation or victim impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84458 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84458

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84458 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84458

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.