Zammad

Zammad

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 0.26%
  • Veröffentlicht 30.09.2026 16:21:20
  • Zuletzt bearbeitet 07.10.2026 17:58:50

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

9.8

CVE-2026-102489

Warnung Medienbericht
  • EPSS 0.58%
  • Veröffentlicht 30.09.2026 16:21:19
  • Zuletzt bearbeitet 07.10.2026 18:03:07

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying frame...

  • EPSS 0.31%
  • Veröffentlicht 25.09.2026 18:23:47
  • Zuletzt bearbeitet 28.09.2026 14:45:39

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide this token in t...

  • EPSS 0.48%
  • Veröffentlicht 25.09.2026 18:23:13
  • Zuletzt bearbeitet 29.09.2026 19:17:26

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent views the conte...

  • EPSS 0.29%
  • Veröffentlicht 25.09.2026 18:22:40
  • Zuletzt bearbeitet 28.09.2026 14:45:39

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI provider error me...

  • EPSS 0.21%
  • Veröffentlicht 25.09.2026 18:21:55
  • Zuletzt bearbeitet 28.09.2026 14:45:39

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a registered sender...

  • EPSS 0.32%
  • Veröffentlicht 25.09.2026 18:21:20
  • Zuletzt bearbeitet 28.09.2026 14:45:39

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response als...

  • EPSS 0.17%
  • Veröffentlicht 25.09.2026 18:20:44
  • Zuletzt bearbeitet 29.09.2026 19:17:26

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses do not consist...

  • EPSS 0.12%
  • Veröffentlicht 25.09.2026 18:19:58
  • Zuletzt bearbeitet 29.09.2026 19:17:27

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it only checks whet...

  • EPSS 0.15%
  • Veröffentlicht 25.09.2026 18:19:19
  • Zuletzt bearbeitet 29.09.2026 20:17:27

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer is rendered, t...