CVE-2026-56730Low· 2.1▾ SunlitZammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to acces…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 11.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to access. The vulnerable GraphQL mutation is meant to transform a knowledge base answer suggestion so it can be inserted into the ticket editor, but it only checks if the user has the ticket.agent permission. Checking the authorization to the knowledge base answer itself is missing. This vulnerability is fixed in 7.0.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56726Medium· 5.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-56724High· 7.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-63205Medium· 5.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-63204Low· 2.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-56734Medium· 5.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-56733High· 8.7Zammad is a web based open source helpdesk/customer support system