PT-2026-98950 · Zammad · Zammad
CVE-2026-61525
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad version 7.0.2
Zammad version 7.1.0
Description
Session management for websocket and long-polling connections is susceptible to a path traversal attack, which occurs when an application uses user-controllable input to construct a path to a file or directory without sufficient validation. When the default file-based session store is active, an authenticated attacker with low privileges can manipulate the session identifier to reference locations outside the intended storage directory, allowing for the deletion of arbitrary files and directories on the server via a single crafted request.
Recommendations
Update Zammad version 7.0.2 to 7.0.3.
Update Zammad version 7.1.0 to 7.1.1.
Use a Redis-based session store instead of the file-based session store.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad