CVE-2026-56729Low· 2.1▾ SunlitZammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledge_base.editor in one category can see answer titles and updated_at …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 11.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledge_base.editor in one category can see answer titles and updated_at timestamps from categories they do not have editor access to , via the global quick search. Category names are not leaked, and opening the answer returns "Page not found," but the title alone may disclose sensitive information. This vulnerability is fixed in 7.0.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63207Medium· 6.9Zammad: Sensitive Information Exposure in Integration Administration API
CVE-2026-84464High· 7.1Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization data
CVE-2026-56728Medium· 5.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-84460Medium· 5.3Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration
CVE-2026-63205Medium· 5.1Zammad: Channel admins can read unauthorized attachments via signature rich-text body
CVE-2026-84463Medium· 6.3Zammad: Stored HTML injection in Knowledge Base video widget enables forced session switching via unescaped iframe attribute