CVE-2026-56725
- EPSS 0.41%
- Veröffentlicht 25.09.2026 17:09:05
- Zuletzt bearbeitet 29.09.2026 20:17:20
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roughly two minutes. The import_check and import_status...
CVE-2026-56732
- EPSS 0.2%
- Veröffentlicht 25.09.2026 17:08:20
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, the injected el...
CVE-2026-56730
- EPSS 0.35%
- Veröffentlicht 25.09.2026 17:07:02
- Zuletzt bearbeitet 29.09.2026 20:17:20
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to access. The vulner...
CVE-2026-56733
- EPSS 0.27%
- Veröffentlicht 25.09.2026 17:05:56
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement of access res...
CVE-2026-56731
- EPSS 0.24%
- Veröffentlicht 25.09.2026 17:04:50
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket creation workflo...
CVE-2026-56735
- EPSS 0.42%
- Veröffentlicht 25.09.2026 17:04:03
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent remote content loading, but the srcset attribute, also allowlisted for ,...
CVE-2026-56727
- EPSS 0.25%
- Veröffentlicht 25.09.2026 17:02:39
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the gpg verification call was silently discarded. Regardless of whether gpg reported a valid, in...
CVE-2026-56734
- EPSS 0.4%
- Veröffentlicht 25.09.2026 17:01:46
- Zuletzt bearbeitet 29.09.2026 20:17:21
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target address. An actor w...
CVE-2026-56726
- EPSS 0.34%
- Veröffentlicht 25.09.2026 17:01:00
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with no active tickets assigned to them, can view the t...
CVE-2026-56729
- EPSS 0.38%
- Veröffentlicht 25.09.2026 16:58:05
- Zuletzt bearbeitet 28.09.2026 14:45:39
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledge_base.editor in one category can see answer titles and updated_at timestamps fr...