Sep 16, 2026
Critical Security Advisory: Authentication bypass in the Generic Interface when using HTTPBasicAuth SSO
A critical authentication bypass affects Znuny installations that use HTTP Basic Authentication (AuthModule HTTPBasicAuth) for single sign-on and have the Generic Interface enabled. A remote attacker can execute Generic Interface operations without authentication.
- News