๐Ÿ” CVE Alert

CVE-2026-84461

UNKNOWN 0.0

Zammad: Missing rate limiting allows password brute-forcing during two-factor login

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2.

CWE CWE-203 CWE-307 CWE-799
Vendor zammad
Product zammad
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for zammad zammad

Be the first to know when new unknown vulnerabilities affecting zammad zammad are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zammad / zammad
< 7.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zammad/zammad/security/advisories/GHSA-6vh5-pfp2-5rmh github.com: https://github.com/zammad/zammad/commit/d51254f1c6da13f6ee27636a5c82e53f7e59666b