Missing Authorization in Zammad - #VU153212

 

Missing Authorization in Zammad - #VU153212

Published: October 3, 2026


Vulnerability identifier: #VU153212
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose internal reply templates.

The vulnerability exists due to missing authorization in direct retrieval of text modules when retrieving an individual group-restricted or deactivated text module. A remote user can directly retrieve a restricted text module to disclose internal reply templates.

Ticket and customer data are not affected, and text modules cannot be modified through this issue.


Affected software

Zammad

Remediation

Install security update from vendor's website.

Zammad - update to 7.1.3

External References

Related Security Bulletins