Missing Authorization in Zammad - #VU153212
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose internal reply templates.
The vulnerability exists due to missing authorization in direct retrieval of text modules when retrieving an individual group-restricted or deactivated text module. A remote user can directly retrieve a restricted text module to disclose internal reply templates.
Ticket and customer data are not affected, and text modules cannot be modified through this issue.