Zammad Cross-Site Request Forgery Vulnerability in OAuth Callback Endpoints

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Zammad, a web-based open-source helpdesk and customer support system. This issue affects versions of Zammad prior to 7.0.1 and 6.5.4. The vulnerability arises because the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not properly validate a CSRF state parameter. As a result, an attacker could potentially exploit this weakness to manipulate the OAuth authentication process.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, by exploiting the lack of CSRF protection in the OAuth callback process.

Remediation

Users can upgrade to Zammad versions 7.0.1 or 6.5.4 to address this vulnerability.

Added: Apr 8, 2026, 8:18 PM
Updated: Apr 8, 2026, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
6.2
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.