Zammad vulnerabilities
CVEs whose affected-version data names the Zammad package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
33 CVEsRSS
CVE-2026-102490High· 8.5All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
CVE-2026-102489High· 8.7Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environm…
CVE-2026-84460Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for the given ticket, regardless of whether they have …
CVE-2026-63205Medium· 5.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img t…
CVE-2026-84463Medium· 6.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer i…
CVE-2026-63206Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can be bypassed using a shortened URL format that omits the doubl…
CVE-2026-63216Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, t…
CVE-2026-84465High· 7.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it onl…
CVE-2026-63207Medium· 6.9Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses d…
CVE-2026-63006Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent vi…
CVE-2026-84461Medium· 6.9Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The…
CVE-2026-63204Low· 2.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI prov…
CVE-2026-63208Medium· 5.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide th…
CVE-2026-84464High· 7.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whether a user was allowed to see a speci…
CVE-2026-84458Critical· 9.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon" setting is enabled, Zammad binds an incoming third-party (SSO) identity to an existing local account b…
CVE-2026-61855Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of inbound PGP-signed email can mark a message as carrying a valid ("Good") PGP signature from a regi…
CVE-2026-56734Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target addres…
CVE-2026-56733High· 8.7Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive validation within the authorization cascade. It has been determined that the system-level enforcement …
CVE-2026-56726Medium· 5.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with no active tickets assigned to them, c…
CVE-2026-56735Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in to prevent remote content loading, but the srcset attribute, also allo…
CVE-2026-56731High· 8.4Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket cre…
CVE-2026-56730Low· 2.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to acces…
CVE-2026-56728Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in Zammad's GraphQL API. An authenticated user can access taskbar item data belonging to another user by cra…
CVE-2026-56725High· 8.7Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST /api/v1/import/otrs/import_check blocks a Zammad request worker for roughly two minutes. The import_check and …
CVE-2026-84462High· 8.6Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent configuration can be bypassed by entering specially crafted text into one of an AI Agent's fields. An a…
CVE-2026-65828Low· 2.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that …
CVE-2026-61525High· 8.8Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the…
CVE-2026-56732Medium· 5.3Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, th…
CVE-2026-56727High· 7.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the return value of the gpg verification call was silently discarded. Regardless of whether gpg reporte…
CVE-2026-56724High· 7.1Zammad is a web based open source helpdesk/customer support system
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked i…