CVE-2026-63205Medium· 5.1▾ SunlitZammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 28.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a new signature-owned record, without checking whether the user has permission to access the original attachment. The newly created copy is then downloadable by the same channel-admin user, because attachment access is determined by the copy's owner (the signature), not the original object (e.g., a ticket or knowledge-base article). This allows a user with any of the admin.channel_email, admin.channel_google, admin.channel_microsoft365, or admin.channel_microsoft_graph permissions to read attachments they would otherwise be denied access to, such as ticket attachments belonging to groups they are not a member of. This issue is fixed in version 7.1.2.
zammad < 7.1.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63204Low· 2.3Zammad: Authenticated agents can read AI summary error messages from inaccessible tickets
CVE-2026-56724High· 7.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-84460Medium· 5.3Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration
CVE-2026-84464High· 7.1Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization data
CVE-2026-56726Medium· 5.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-56730Low· 2.1Zammad is a web based open source helpdesk/customer support system