VulnSea

Zammad vulnerabilities

CVEs whose affected-version data names the Zammad package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

33 CVEsRSS

CVE-2026-102490High· 8.5
today

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

▾ TwilightZammad GmbH · Zammadvia NVD
CVE-2026-102489High· 8.7
today

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environm…

▾ TwilightZammad GmbH · Zammadvia NVD
CVE-2026-84460Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for the given ticket, regardless of whether they have …

▾ Sunlitzammad · zammadEPSS 0.26%via NVD
CVE-2026-63205Medium· 5.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img t…

▾ Sunlitzammad · zammadEPSS 0.32%via NVD
CVE-2026-84463Medium· 6.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer i…

▾ Sunlitzammad · zammadEPSS 0.15%via NVD
CVE-2026-63206Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can be bypassed using a shortened URL format that omits the doubl…

▾ Sunlitzammad · zammadEPSS 0.28%via NVD
CVE-2026-63216Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, t…

▾ Sunlitzammad · zammadEPSS 0.24%via NVD
CVE-2026-84465High· 7.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it onl…

▾ Twilightzammad · zammadEPSS 0.12%via NVD
CVE-2026-63207Medium· 6.9
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses d…

▾ Sunlitzammad · zammadEPSS 0.17%via NVD
CVE-2026-63006Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent vi…

▾ Sunlitzammad · zammadEPSS 0.48%via NVD
CVE-2026-84461Medium· 6.9
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The…

▾ Sunlitzammad · zammadEPSS 0.32%via NVD
CVE-2026-63204Low· 2.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI prov…

▾ Sunlitzammad · zammadEPSS 0.29%via NVD
CVE-2026-63208Medium· 5.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide th…

▾ Sunlitzammad · zammadEPSS 0.31%via NVD
CVE-2026-84464High· 7.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a speci…

▾ Twilightzammad · zammadEPSS 0.29%via NVD
CVE-2026-84458Critical· 9.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account b…

▾ Midnightzammad · zammadEPSS 0.36%via NVD
CVE-2026-61855Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a regi…

▾ Sunlitzammad · zammadEPSS 0.21%via NVD
CVE-2026-56734Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target addres…

▾ Sunlitzammad · zammadEPSS 0.40%via NVD
CVE-2026-56733High· 8.7
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement …

▾ Twilightzammad · zammadEPSS 0.27%via NVD
CVE-2026-56726Medium· 5.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with no active tickets assigned to them, c…

▾ Sunlitzammad · zammadEPSS 0.34%via NVD
CVE-2026-56735Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent remote content loading, but the srcset attribute, also allo…

▾ Sunlitzammad · zammadEPSS 0.42%via NVD
CVE-2026-56731High· 8.4
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket cre…

▾ Twilightzammad · zammadEPSS 0.24%via NVD
CVE-2026-56730Low· 2.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to acces…

▾ Sunlitzammad · zammadEPSS 0.35%via NVD
CVE-2026-56728Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in Zammad's GraphQL API. An authenticated user can access taskbar item data belonging to another user by cra…

▾ Sunlitzammad · zammadEPSS 0.33%via NVD
CVE-2026-56725High· 8.7
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roughly two minutes. The import_check and …

▾ Twilightzammad · zammadEPSS 0.41%via NVD
CVE-2026-84462High· 8.6
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An a…

▾ Twilightzammad · zammadEPSS 0.28%via NVD
CVE-2026-65828Low· 2.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that …

▾ Sunlitzammad · zammadEPSS 0.20%via NVD
CVE-2026-61525High· 8.8
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the…

▾ Twilightzammad · zammadEPSS 0.36%via NVD
CVE-2026-56732Medium· 5.3
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, th…

▾ Sunlitzammad · zammadEPSS 0.20%via NVD
CVE-2026-56727High· 7.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the gpg verification call was silently discarded. Regardless of whether gpg reporte…

▾ Twilightzammad · zammadEPSS 0.25%via NVD
CVE-2026-56724High· 7.1
5d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked i…

▾ Twilightzammad · zammadEPSS 0.27%via NVD
Zammad vulnerabilities (CVEs) · VulnSea