Direct-Request SSRF via Zammad Webhooks (CVE-2026-34719)
A webhook endpoint that accepted internal IPs with no range validation, turned into a clean data-exfiltration primitive by Zammad’s own HTTP logs.
A webhook endpoint that accepted internal IPs with no range validation, turned into a clean data-exfiltration primitive by Zammad’s own HTTP logs.