CVE-2026-34721 | Zammad up to 6.5.3/7.0.0 OAuth Callback Endpoint cross-site request forgery (WID-SEC-2026-1000)
A vulnerability was found in Zammad up to 6.5.3/7.0.0 and classified as problematic. This impacts an unknown function of the component OAuth Callback Endpoint. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is tracked as CVE-2026-34721. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.