PT-2026-99081 · Zammad · Zammad

CVE-2026-63206

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description The HTML sanitizer used in ticket articles and email views fails to correctly identify and block remote images when a shortened URL format is used that omits the double slash after the scheme. Because modern browsers treat these shortened formats as equivalent to standard remote URLs, an attacker can send a crafted email or ticket that forces the recipient's browser to silently load an image from an external server. This allows the attacker to determine when and by whom the ticket was opened while bypassing the remote content blocked warning.
Recommendations Update Zammad to version 7.1.2.

Exploit

Fix

RCE

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63206
GHSA-FPWP-W2P4-HQG7

Affected Products

Zammad