Inappropriate Encoding for Output Context in Zammad - CVE-2026-84463
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to switch another user's session to an attacker-chosen account.
The vulnerability exists due to inappropriate encoding for output context in the Knowledge Base video widget iframe attribute when rendering a published Knowledge Base answer containing a crafted video widget value. A remote user can embed a video widget with a specially crafted value to switch another user's session to an attacker-chosen account.
The viewer must have permission to switch between user sessions, and opening the published answer is sufficient to trigger the request.