Missing Authorization in Zammad - #VU153211
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in inline image handling in HTML notification emails when processing a crafted incoming email quoted in an HTML notification. A remote attacker can send a crafted email to cause arbitrary stored files to be included as attachments in a reply to disclose sensitive information.
Exploitation requires a trigger or scheduler configured to send notification emails that quote incoming messages in HTML.