PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84464 zammad CVE debrief

CVE-2026-84464 is a vulnerability in Zammad, an open-source helpdesk/customer support system. An authenticated user could exploit this vulnerability to view details of tickets, customer accounts, teams, or organizations that did not belong to them by referencing another record's ID in the External Data Source feature. This issue is fixed in version 7.1.2.

Vendor
zammad
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Zammad installations, security teams, and administrators of customer support systems should assess exposure and apply the patch to prevent unauthorized information access.

Why it matters

CVE-2026-84464 is a vulnerability in Zammad that allows authenticated users to access unauthorized information. Defenders should prioritize verifying exposure and applying the patch to prevent potential data breaches and unauthorized access.

  • Potential unauthorized access to sensitive information
  • Increased risk of data breaches
  • Need for verification of user permissions and access controls
  • Priority on patching vulnerable systems

Technical summary

The External Data Source feature in Zammad did not properly verify user permissions before including ticket, user, group, or organization details in requests to external systems. An authenticated user could exploit this by referencing another record's ID to view unauthorized information, potentially leading to unauthorized access to sensitive information and increased risk of data breaches. Defenders should prioritize verifying exposure and applying the patch to prevent potential data breaches and unauthorized access.

Defensive priority

Defenders should prioritize verifying exposure and applying the patch, as this vulnerability allows authenticated users to access unauthorized information.

Recommended defensive actions

  • Verify if the system is using a version of Zammad prior to 7.1.2 and apply the patch if necessary.
  • Restrict access to the External Data Source feature to authorized users only.
  • Monitor for any suspicious activity related to unauthorized information access.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, additional information on exploitation or affected systems is limited. Defenders should verify the patch is applied and monitor for suspicious activity related to unauthorized information access. The External Data Source feature's improper verification of user permissions could allow authenticated users to access unauthorized information by referencing another record's ID.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84464 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84464

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84464 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84464

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.