SB2026100308 - Multiple vulnerabilities in Zammad
Published: October 3, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in inline image handling in HTML notification emails when processing a crafted incoming email quoted in an HTML notification. A remote attacker can send a crafted email to cause arbitrary stored files to be included as attachments in a reply to disclose sensitive information.
Exploitation requires a trigger or scheduler configured to send notification emails that quote incoming messages in HTML.
2) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose internal reply templates.
The vulnerability exists due to missing authorization in direct retrieval of text modules when retrieving an individual group-restricted or deactivated text module. A remote user can directly retrieve a restricted text module to disclose internal reply templates.
Ticket and customer data are not affected, and text modules cannot be modified through this issue.
3) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read and modify other users' overview ordering preferences.
The vulnerability exists due to authorization bypass through a user-controlled key in the personal overview ordering endpoints when handling requests to manage overview ordering preferences. A remote user can access, modify, delete, or create overview ordering preferences for other users to read and modify other users' overview ordering preferences.
The impact is limited to ticket overview ordering and sorting; no ticket content or other personal data is exposed.
4) Insufficiently protected credentials (CVE-ID: N/A)
CWE-ID: CWE-522 - Insufficiently Protected Credentials
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose external data source credentials.
The vulnerability exists due to improper access control in object attribute metadata when retrieving object attribute configurations. A remote user can retrieve object attribute metadata to disclose external data source credentials.
Only instances configured with an external data source attribute containing access data are affected.
5) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in the Core Workflow perform endpoint when processing requests that name records. A remote user can name a record in a request to disclose sensitive information.
Ticket data and stored passwords remain protected.
6) Improper Neutralization of Script in Attributes in a Web Page (CVE-ID: N/A)
CWE-ID: CWE-83 - Improper Neutralization of Script in Attributes in a Web Page
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to present misleading links or inject unwanted content into the page.
The vulnerability exists due to improper output escaping in AI error messages when displaying AI error messages containing link-style text. A remote user can influence AI error text containing link-style text to present misleading links or inject unwanted content into the page.
AI features must be enabled, and user interaction is required.
7) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: N/A)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access internal-only network resources.
The vulnerability exists due to a time-of-check time-of-use race condition in the hostname safety check when validating and fetching an attacker-supplied URL. A remote attacker can manipulate DNS responses for a controlled domain to direct requests to internal addresses.
An administrator must configure the attacker-supplied URL, and exploitation depends on a DNS-timing race.
Remediation
Install update from vendor's website.
References
- https://github.com/zammad/zammad/security/advisories/GHSA-49h2-vrqp-wwwf
- https://github.com/zammad/zammad/security/advisories/GHSA-36hv-g4ch-ch33
- https://github.com/zammad/zammad/security/advisories/GHSA-r4qw-cv8j-3wf6
- https://github.com/zammad/zammad/security/advisories/GHSA-g3cf-rfq7-j5cr
- https://github.com/zammad/zammad/security/advisories/GHSA-3ww3-89pm-g9x8
- https://github.com/zammad/zammad/security/advisories/GHSA-cq4j-rx79-345g
- https://github.com/zammad/zammad/security/advisories/GHSA-pfh2-5g93-2rg6