CVE-2026-63207Medium· 6.9▾ SunlitZammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses d…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses do not consistently mask sensitive fields, so configured secrets can be returned in plain text instead of the expected masked placeholder. Both the LDAP and Exchange integrations are affected. This issue is fixed in version 7.1.2.
zammad < 7.1.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84464High· 7.1Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organization data
CVE-2026-56728Medium· 5.3Zammad is a web based open source helpdesk/customer support system
CVE-2026-56729Low· 2.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-84460Medium· 5.3Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration
CVE-2026-63205Medium· 5.1Zammad: Channel admins can read unauthorized attachments via signature rich-text body
CVE-2026-84463Medium· 6.3Zammad: Stored HTML injection in Knowledge Base video widget enables forced session switching via unescaped iframe attribute