How to use this reference
Editorial lesson: a model override must retain the security contract of its base implementation. Bind serialization to the requesting actor and the resource group before response construction; review inherited and specialized serializers together.
Before reading
- Basic understanding of server-side object authorization and resource ownership
Context and limits
- The case requires an authenticated agent-role user. Documented impact is reading tickets and associated information outside permitted groups. The research summary mentions possible manipulation, but its impact section and vendor notice substantiate disclosure; this record makes no demonstrated-write claim.
- GitHub Security Lab reported February 17, 2026; the maintainer identified it as a duplicate February 18. GHSL credits Taskflow Agent discovery with manual verification by Peter Stöckli and Man Yue Mo. Vendor ZAA-2026-05 credits Sho Odagiri of GMO Cybersecurity; preserve both attributions.
- Vendor ZAA-2026-05 displays March 4, 2026 above a February 25 advisory-detail date. It lists fixes in 7.0.0 and 6.5.3 and says SaaS remediation was handled. GHSL dates the 7.0.0 patch release March 4. A release-specific date for 6.5.3 is not established here.
- The reviewed notice still says CVE assignment pending. No bounty amount, customer incident count, or independent deployment verification is supplied. Learning prerequisites and design lessons are editorial.
Sources and provenance
- GHSL-2026-049: An Insecure Direct Object Reference (IDOR) in Zammad Leads to Access Control Violations GitHub Security Lab · reviewed 2026-10-03
- Security Advisory ZAA-2026-05 Zammad · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.