PT-2026-99088 · Zammad · Zammad

CVE-2026-84463

·

Published

2026-09-25

·

Updated

2026-09-29

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.1.2
Description Users with Knowledge Base editing rights for a category can embed a video widget in a published answer using a specially crafted value. Because this value is inserted into the page HTML without being escaped for its attribute context, it allows the injection of additional HTML. When a user with session-switching permissions views the affected answer, the injected HTML triggers a silent request to the session-switching endpoint using the viewer's active credentials. This action switches the viewer's session to an account selected by the author of the Knowledge Base answer.
Recommendations Update to version 7.1.2.

Exploit

Fix

XSS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84463
GHSA-CXJG-4GMF-5XQC

Affected Products

Zammad