PT-2026-98942 · Zammad · Zammad

CVE-2026-56728

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.2
Description Broken access control in the GraphQL API allows an authenticated user to access taskbar item data belonging to another user. By crafting a request with the target user's taskbar identifier, an attacker can read transient state data for active user sessions, which may include auto-saved ticket drafts, because the authorization check for taskbar item access is not consistently enforced.
Recommendations Update to version 7.0.2.

Exploit

Fix

Information Disclosure

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56728
GHSA-JVCG-5539-VVC3

Affected Products

Zammad