PT-2026-99083 · Zammad · Zammad

CVE-2026-63208

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description When a Microsoft Graph request fails, the system logs the error including the authentication token used to access the mailbox. Although the system attempts to mask the token, the process is incomplete for the JSON Web Token (JWT) format used by Microsoft. Only the first part of the token is hidden, leaving the remaining parts in plain text. A Zammad administrator with Microsoft Graph channel access can view these logs and see the partial token, which may reveal sensitive claims such as the account scope, tenant, or timing, potentially assisting in the reconstruction of the full token while it remains valid.
Recommendations Update to version 7.1.2.

Exploit

Fix

Insertion into Log File

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63208
GHSA-QH8M-G5VR-7272

Affected Products

Zammad