EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all intelligence correlata
Vulnerabilità

CVE-2026-84461

Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.

Condivisione
PUBLIC-OSINT
Confidenza
100
Fonte
The CVE Program
Aggiornata
26/09/2026 02:36

Descrizione

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed whether a guess was correct, even before two-factor authentication was checked. This made it possible to brute-force weak or reused passwords. This issue is fixed in version 7.1.2.

Identificativo STIXvulnerability--196ed274-e2a6-5a5d-ab72-d9b229925de9
Prima osservazione-
Ultima osservazione-
Relazioni censite10

Alias e classificazioni

CWE-203CWE-307CWE-799Improper Control of Interaction FrequencyImproper Restriction of Excessive Authentication AttemptsObservable Discrepancy

Dettagli tecnici minimizzati

Nessun dato grezzo
cisa kev
False
Correlazione EudorIA

Catalogo Intel

La vulnerabilità è presente anche nel catalogo editoriale EudorIA.

Apri analisi EudorIA

La presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.