CVE-2020-26032
NixOS vulnerability analysis and mitigation

Overview

An SSRF (Server-Side Request Forgery) vulnerability was discovered in Zammad versions prior to 3.4.1. The vulnerability, tracked as CVE-2020-26032, was found in the SMS configuration interface for Massenversand functionality. The issue affects Zammad versions 1.0.x through 3.4.0 and was fixed in versions 3.4.1 and 3.5.0 (Zammad Advisory).

Technical details

The vulnerability exists in the SMS configuration interface where the application renders the result of test requests to the user. This implementation allows an attacker to make GET requests to arbitrary URLs from the server's network interface. The vulnerability was rated as medium severity (Zammad Advisory).

Impact

The SSRF vulnerability could allow attackers to send unauthorized requests from the system to internal resources. This could potentially lead to the disclosure of sensitive information from internal systems that should not be accessible from external networks (Zammad Advisory).

Exploitability

An attacker can exploit this vulnerability by manipulating the SMS configuration interface to make requests to arbitrary URLs, which are then processed and rendered by the server (Zammad Advisory).

Mitigation and workarounds

The vulnerability was fixed in Zammad versions 3.4.1 and 3.5.0. Users are recommended to upgrade to one of these fixed versions. Updates can be obtained through the official Zammad website, FTP server, or through the OS package manager (Zammad Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher Michał Błaszczak, who works with Zdalny Admln (Zammad Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management