PT-2026-99081 · Zammad · Zammad
CVE-2026-63206
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
The HTML sanitizer used in ticket articles and email views fails to correctly identify and block remote images when a shortened URL format is used that omits the double slash after the scheme. Because modern browsers treat these shortened formats as equivalent to standard remote URLs, an attacker can send a crafted email or ticket that forces the recipient's browser to silently load an image from an external server. This allows the attacker to determine when and by whom the ticket was opened while bypassing the remote content blocked warning.
Recommendations
Update Zammad to version 7.1.2.
Exploit
Fix
RCE
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad