Vulnerability Bulletins |
CVE-2026-34721 |
|
| Affected software | MICROSOFT |
| Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This vulnerability is fixed in 7.0.1 and 6.5.4. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-34721 | |






