PT-2026-99089 · Zammad · Zammad
CVE-2026-84464
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.1.2
Description
The External Data Source feature, which retrieves records from external systems, fails to properly verify user permissions before including record details in requests. An authenticated user with basic customer access can reference a record ID to view unauthorized details of tickets, customer accounts, teams, or organizations.
Recommendations
Update to version 7.1.2.
Exploit
Fix
Incorrect Authorization
Information Disclosure
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad