Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zammad
Zammad zammad |
|
| Vendors & Products |
Zammad
Zammad zammad |
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2. | |
| Title | Zammad: Missing rate limiting allows password brute-forcing during two-factor login | |
| Weaknesses | CWE-203 CWE-307 CWE-799 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-25T18:41:14.822Z
Reserved: 2026-09-01T20:05:09.424Z
Link: CVE-2026-84461
Updated: 2026-09-25T18:41:11.529Z
Status : Received
Published: 2026-09-25T19:17:57.467
Modified: 2026-09-25T19:17:57.467
Link: CVE-2026-84461
No data.
OpenCVE Enrichment
Updated: 2026-09-26T10:00:15Z