Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around this prevention, enabling them to send more than the configured amount of requests before the user invalidation takes place.
Cite this page
CVE-2022-35490. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-35490
Use CWE-307, Zammad vendor hub and Zammad product page to widen CVE-2022-35490 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34724, CVE-2026-34723 and CVE-2026-34719 for nearby disclosures in the same product family.