PT-2026-31418 · Microsoft+3 · Microsoft+3

Published

2026-04-08

·

Updated

2026-04-09

·

CVE-2026-34721

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1 and prior to 6.5.4
Description The OAuth callback endpoints for Microsoft, Google, and Facebook external credentials do not validate a CSRF state parameter. This could allow an attacker to potentially compromise accounts.
Recommendations Update to version 7.0.1 or later. Update to version 6.5.4 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34721

Affected Products

Facebook
Google
Microsoft
Zammad