PT-2026-99084 · Zammad · Zammad

CVE-2026-63216

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description Unsanitized option labels are rendered as raw HTML without escaping in the configuration dialogs of AI Agents within the admin UI. An attacker can inject arbitrary HTML and JavaScript by controlling an option label, such as by using a malicious string for a user or organization name in a relation attribute or providing a crafted custom attribute option value. The injected payload executes in the browser of any administrator or agent who accesses the affected object attribute configuration view.
Recommendations Update to version 7.1.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63216
GHSA-R95M-GHJ7-646X

Affected Products

Zammad