PT-2026-99080 · Zammad · Zammad
CVE-2026-63205
·
Published
2026-09-25
·
Updated
2026-09-29
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
When creating or updating an email signature, the system processes inline images in the signature body. If an HTML img tag points to an existing attachment, the system copies that attachment into a new record owned by the signature without verifying if the user has permission to access the original file. Since access to the copy is determined by the signature's owner rather than the original object, users with
admin.channel email, admin.channel google, admin.channel microsoft365, or admin.channel microsoft graph permissions can download attachments they are not authorized to view, such as ticket attachments from groups they do not belong to.Recommendations
Update to version 7.1.2.
Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad