CVE-2026-84464
- EPSS 0.29%
- Veröffentlicht 25.09.2026 18:18:40
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a specific ticket, u...
CVE-2026-63216
- EPSS 0.24%
- Veröffentlicht 25.09.2026 18:16:01
- Zuletzt bearbeitet 29.09.2026 20:17:21
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, the option lab...
CVE-2026-84458
- EPSS 0.36%
- Veröffentlicht 25.09.2026 18:15:26
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account by matching th...
CVE-2026-84460
- EPSS 0.26%
- Veröffentlicht 25.09.2026 18:14:49
- Zuletzt bearbeitet 29.09.2026 19:17:26
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for the given ticket, regardless of whether they have access to tha...
CVE-2026-63206
- EPSS 0.28%
- Veröffentlicht 25.09.2026 18:14:06
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can be bypassed using a shortened URL format that omits the double slash after...
CVE-2026-63205
- EPSS 0.32%
- Veröffentlicht 25.09.2026 18:13:25
- Zuletzt bearbeitet 29.09.2026 20:17:21
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing t...
CVE-2026-84462
- EPSS 0.28%
- Veröffentlicht 25.09.2026 17:29:15
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An administrator ...
CVE-2026-65828
- EPSS 0.2%
- Veröffentlicht 25.09.2026 17:28:13
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that the requestin...
CVE-2026-61525
- EPSS 0.36%
- Veröffentlicht 25.09.2026 17:11:33
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are i...
CVE-2026-56728
- EPSS 0.33%
- Veröffentlicht 25.09.2026 17:10:16
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in Zammad's GraphQL API. An authenticated user can access taskbar item data belonging to another user by crafting a reque...