CVE-2026-84464
Last modified
CVE-2026-84464 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specific ticket, user, group, or organization before including its details in a request to that external system.
Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specific ticket, user, group, or organization before including its details in a request to that external system. An authenticated user, including one with only basic customer access, could exploit this by referencing another record's ID, and thereby view details of tickets, customer accounts, teams, or organizations that did not belong to them. This issue is fixed in version 7.1.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zammad | zammad | < 7.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-84464?
How severe is CVE-2026-84464?
How do I fix CVE-2026-84464?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84458Zammad is a web based open source helpdesk/customer support …9.1
- CVE-2026-8446IBM Langflow OSS 1.0.0 through 1.10.3 contain an authenticat…7.5
- CVE-2026-84460Zammad is a web based open source helpdesk/customer support …5.3
- CVE-2026-84461Zammad is a web based open source helpdesk/customer support …6.9
- CVE-2026-84462Zammad is a web based open source helpdesk/customer support …8.6
- CVE-2026-84463Zammad is a web based open source helpdesk/customer support …6.3
- CVE-2026-84465Zammad is a web based open source helpdesk/customer support …7.1
- CVE-2026-84469fastify versions before 5.12.2 decide whether to compile a r…7.5
- CVE-2026-8447IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored c…6.1
- CVE-2026-84470A flaw was found in Ansible Automation Platform's automation…6.4
- CVE-2026-84474A flaw was found in Red Hat Ansible Automation Platform's au…9.9
- CVE-2026-84476WWBN AVideo fails to validate trusted proxies before accepti…7.5
Are you affected by CVE-2026-84464?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
