CVE-2026-34721
Vulnerability Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-352
Source
NVD
Vendor
zammad
Product
zammad
Discussion (0)
Add Comment
No comments yet. Be the first!