Zendesk Email Spoofing Vulnerability Allows Unauthorized Access to Ticket History

Vulnerability

A vulnerability in Zendesk's email handling system prior to July 2, 2024, allows remote attackers to read ticket histories by spoofing email addresses. This issue arises because the Cc fields in incoming emails are used to grant additional access to ticket information, and Zendesk's mechanisms for verifying email authenticity are inadequate. The vulnerability is exacerbated by the predictability of support email addresses linked to individual tickets.

Impact

Exploitation of this vulnerability enables unauthorized users to access private Zendesk tickets by spoofing emails and adding themselves as Cc recipients, thereby reading sensitive information contained in the tickets.

Reproduction

The vulnerability can be reproduced by creating an Apple ID or Google account with a support email address, then sending a spoofed email to a specific Zendesk ticket ID. This process involves CCing the attacker's email to gain access to the ticket history. The spoofed email bypasses Zendesk's email verification checks, allowing unauthorized access to the ticketing system.

Remediation

Zendesk has implemented measures to enhance their email verification process and block spoofed emails from certain sources. However, companies using Zendesk should review their email collaboration settings to prevent unauthorized access to ticket information.

Added: Jun 22, 2026, 10:22 AM
Updated: Jun 22, 2026, 10:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.