Zammad
Products
2- 121 CVEs
- 1 CVE
Recent CVEs
121| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48021 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server. | ||
| CVE-2022-35490 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2022 | Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling… | ||
| CVE-2021-42090 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled. | ||
| CVE-2021-42094 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages. | ||
| CVE-2020-26030 | Cri | 0.64 | 9.8 | 0.01 | Dec 28, 2020 | An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users. | ||
| CVE-2017-6080 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2017 | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users… | ||
| CVE-2017-5619 | Cri | 0.64 | 9.8 | 0.02 | Mar 13, 2017 | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string. | ||
| CVE-2022-27332 | Cri | 0.59 | 9.1 | 0.01 | Apr 27, 2022 | An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS). | ||
| CVE-2021-42091 | Cri | 0.59 | 9.1 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration. | ||
| CVE-2021-42086 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request. | ||
| CVE-2017-6081 | Hig | 0.57 | 8.8 | 0.01 | Mar 13, 2017 | A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie. | ||
| CVE-2024-33666 | Hig | 0.56 | 8.6 | 0.01 | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents. | ||
| CVE-2021-43145 | Hig | 0.53 | 8.1 | 0.01 | Feb 4, 2022 | With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts. | ||
| CVE-2026-84458 | Cri | 0.52 | — | 0.00 | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity… | ||
| CVE-2024-33668 | Cri | 0.52 | 9.1 | 0.00 | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to. | ||
| CVE-2026-61525 | Hig | 0.50 | — | 0.00 | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are insufficiently validated… | ||
| CVE-2026-56733 | Hig | 0.50 | — | 0.00 | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement of access restrictions during the… | ||
| CVE-2026-56725 | Hig | 0.50 | — | 0.00 | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roughly two minutes. The import_check and import_status actions are missing the… | ||
| CVE-2026-84462 | Hig | 0.49 | — | 0.00 | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An administrator with permission to create or… | ||
| CVE-2023-50455 | Hig | 0.49 | 7.5 | 0.01 | Dec 10, 2023 | An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim). |
- risk 0.64cvss 9.8epss 0.01
A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.
- risk 0.64cvss 9.8epss 0.01
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be used to perform any actions in the name of other users.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.
- risk 0.59cvss 9.1epss 0.01
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.
- risk 0.57cvss 8.8epss 0.01
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.
- risk 0.56cvss 8.6epss 0.01
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
- risk 0.53cvss 8.1epss 0.01
With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.
- risk 0.52cvss —epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching the email address the identity…
- risk 0.52cvss 9.1epss 0.00
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.
- risk 0.50cvss —epss 0.00
Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are insufficiently validated…
- risk 0.50cvss —epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement of access restrictions during the…
- risk 0.50cvss —epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roughly two minutes. The import_check and import_status actions are missing the…
- risk 0.49cvss —epss 0.00
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An administrator with permission to create or…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).