Cross-site scripting in Zammad - CVE-2026-102345
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script.
The vulnerability exists due to improper output encoding in ticket article rendering in the new Vue-based interface when rendering crafted ticket article content. A remote user can submit crafted ticket article content to execute arbitrary script.
User interaction is required to view the ticket.