PT-2026-98946 · Zammad · Zammad

CVE-2026-56732

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.2
Description Zammad is a web-based open source helpdesk and customer support system. A flaw in the HTML sanitization process allows the injection of specific HTML elements into ticket bodies. When a user views a ticket containing these crafted elements, it can trigger an unauthorized logout request, which terminates the viewer's active session.
Recommendations Update to version 7.0.2.

Exploit

Fix

CSRF

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56732
GHSA-6RMM-28J9-Q99Q

Affected Products

Zammad