CVE-2026-63006
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 02:52
Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent views the content, the browser resolves the URL to a protected API endpoint and sends the request with the agent's session cookie, enabling side effects such as forced logout without any user interaction. This issue is fixed in version 7.1.2.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
Public references
- https://github.com/zammad/zammad/security/advisories/GHSA-33p2-cm7w-62g3
https://github.com/zammad/zammad/security/advisories/GHSA-33p2-cm7w-62g3 - https://github.com/zammad/zammad/commit/856af85c12413087d6a74ffee25b16048a5ed8c3
https://github.com/zammad/zammad/commit/856af85c12413087d6a74ffee25b16048a5ed8c3
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.