Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2. | |
| Title | Zammad: Missing rate limiting allows password brute-forcing during two-factor login | |
| Weaknesses | CWE-203 CWE-307 CWE-799 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-25T18:41:14.822Z
Reserved: 2026-09-01T20:05:09.424Z
Link: CVE-2026-84461
Updated: 2026-09-25T18:41:11.529Z
Status : Received
Published: 2026-09-25T19:17:57.467
Modified: 2026-09-25T19:17:57.467
Link: CVE-2026-84461
No data.
OpenCVE Enrichment
Updated: 2026-09-25T19:45:17Z