Insufficiently protected credentials in Zammad - #VU153214
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose external data source credentials.
The vulnerability exists due to improper access control in object attribute metadata when retrieving object attribute configurations. A remote user can retrieve object attribute metadata to disclose external data source credentials.
Only instances configured with an external data source attribute containing access data are affected.