PT-2026-99080 · Zammad · Zammad

CVE-2026-63205

·

Published

2026-09-25

·

Updated

2026-09-29

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description When creating or updating an email signature, the system processes inline images in the signature body. If an HTML img tag points to an existing attachment, the system copies that attachment into a new record owned by the signature without verifying if the user has permission to access the original file. Since access to the copy is determined by the signature's owner rather than the original object, users with admin.channel email, admin.channel google, admin.channel microsoft365, or admin.channel microsoft graph permissions can download attachments they are not authorized to view, such as ticket attachments from groups they do not belong to.
Recommendations Update to version 7.1.2.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63205
GHSA-PP8R-X7PP-5QJ5

Affected Products

Zammad