CVE-2026-84461
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 02:36
Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
Public references
- https://github.com/zammad/zammad/commit/d51254f1c6da13f6ee27636a5c82e53f7e59666b
https://github.com/zammad/zammad/commit/d51254f1c6da13f6ee27636a5c82e53f7e59666b - https://github.com/zammad/zammad/security/advisories/GHSA-6vh5-pfp2-5rmh
https://github.com/zammad/zammad/security/advisories/GHSA-6vh5-pfp2-5rmh
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.