Direct-Request SSRF via Zammad Webhooks (CVE-2026-34719)

A webhook endpoint that accepted internal IPs with no range validation, turned into a clean data-exfiltration primitive by Zammad’s own HTTP logs.

June 3, 2026 · 3 min · k0x1c