PT-2026-99083 · Zammad · Zammad
CVE-2026-63208
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
When a Microsoft Graph request fails, the system logs the error including the authentication token used to access the mailbox. Although the system attempts to mask the token, the process is incomplete for the JSON Web Token (JWT) format used by Microsoft. Only the first part of the token is hidden, leaving the remaining parts in plain text. A Zammad administrator with Microsoft Graph channel access can view these logs and see the partial token, which may reveal sensitive claims such as the account scope, tenant, or timing, potentially assisting in the reconstruction of the full token while it remains valid.
Recommendations
Update to version 7.1.2.
Exploit
Fix
Insertion into Log File
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad