PT-2026-98957 · Zammad · Zammad
CVE-2026-65828
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
An authenticated attacker can silently remove temporary file uploads of another user before a ticket or article is submitted. This occurs because the
destroy form action on the AttachmentsController deletes UploadCache Store records based on a user-supplied form id without verifying ownership of the records. This allows an attacker who obtains a pending-upload UUID to delete the associated files.Recommendations
Update to version 7.1.2.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zammad