CVE-2026-34721

MEDIUM WAF: Low
CVSS 6.5 Published: 2026-04-08
CWE-352

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4.

WAF Coverage Analysis

Cross-Site Request Forgery (CSRF) Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
zammadzammadup to 6.5.4
zammadzammad7.0.0

References

Back to CVE Database