vulns.co
/
GKData.io MCP

GitHub Security Lab · 2 min read

Zammad: overridden serialization must preserve group authorization

GHSL-2026-049 describes a ticket asset serializer that overrode a permission-aware base implementation without preserving its group-access check. GitHub Security Lab reports confidential ticket and associated-user disclosure in tested Zammad 6.5.2; the vendor corroborates unauthorized asset access.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Editorial lesson: a model override must retain the security contract of its base implementation. Bind serialization to the requesting actor and the resource group before response construction; review inherited and specialized serializers together.

Before reading

  • Basic understanding of server-side object authorization and resource ownership

Context and limits

  • The case requires an authenticated agent-role user. Documented impact is reading tickets and associated information outside permitted groups. The research summary mentions possible manipulation, but its impact section and vendor notice substantiate disclosure; this record makes no demonstrated-write claim.
  • GitHub Security Lab reported February 17, 2026; the maintainer identified it as a duplicate February 18. GHSL credits Taskflow Agent discovery with manual verification by Peter Stöckli and Man Yue Mo. Vendor ZAA-2026-05 credits Sho Odagiri of GMO Cybersecurity; preserve both attributions.
  • Vendor ZAA-2026-05 displays March 4, 2026 above a February 25 advisory-detail date. It lists fixes in 7.0.0 and 6.5.3 and says SaaS remediation was handled. GHSL dates the 7.0.0 patch release March 4. A release-specific date for 6.5.3 is not established here.
  • The reviewed notice still says CVE assignment pending. No bounty amount, customer incident count, or independent deployment verification is supplied. Learning prerequisites and design lessons are editorial.

Sources and provenance

  1. GHSL-2026-049: An Insecure Direct Object Reference (IDOR) in Zammad Leads to Access Control Violations GitHub Security Lab · reviewed 2026-10-03
  2. Security Advisory ZAA-2026-05 Zammad · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software