PT-2026-98950 · Zammad · Zammad

CVE-2026-61525

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad version 7.0.2 Zammad version 7.1.0
Description Session management for websocket and long-polling connections is susceptible to a path traversal attack, which occurs when an application uses user-controllable input to construct a path to a file or directory without sufficient validation. When the default file-based session store is active, an authenticated attacker with low privileges can manipulate the session identifier to reference locations outside the intended storage directory, allowing for the deletion of arbitrary files and directories on the server via a single crafted request.
Recommendations Update Zammad version 7.0.2 to 7.0.3. Update Zammad version 7.1.0 to 7.1.1. Use a Redis-based session store instead of the file-based session store.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61525
GHSA-XP9W-HHF3-VFXX

Affected Products

Zammad