PT-2026-98938 · Zammad · Zammad

CVE-2026-56723

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.2
Description An authorization bypass exists where a customer with access to a ticket can download attachments from internal ticket articles. While the article listing API correctly hides internal articles, the attachment download endpoint only verifies access to the parent ticket and fails to check the authorization level of the specific article. This allows unauthorized users to retrieve sensitive files attached to internal notes.
Recommendations Update to version 7.0.2.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56723
GHSA-374G-4F73-G7M7

Affected Products

Zammad