Authorization bypass through user-controlled key in Zammad - #VU153215
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in the Core Workflow perform endpoint when processing requests that name records. A remote user can name a record in a request to disclose sensitive information.
Ticket data and stored passwords remain protected.