CVE-2026-84461: Zammad

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2.

Affected products

  • Zammad Zammad: before 7.1.2 (fixed in 7.1.2)

Published 2026-09-25. Last modified 2026-09-28.