Zammad
32 known vulnerabilities in Zammad, 3 critical, 2 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-102490 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Improper Privilege Management Vulnerability
- CVE-2026-102489 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Session Fixation Vulnerability
Latest vulnerabilities
- CVE-2026-102490 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Improper Privilege Management Vulnerability
- CVE-2026-102489 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Session Fixation Vulnerability
- CVE-2026-84465 CVSS 7.1 high Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an…
- CVE-2026-84464 CVSS 7.1 high Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up…
- CVE-2026-84463 CVSS 6.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a…
- CVE-2026-84461 CVSS 6.9 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try…
- CVE-2026-84460 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for…
- CVE-2026-84458 CVSS 9.1 critical Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on initial logon"…
- CVE-2026-63216 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the…
- CVE-2026-63208 CVSS 5.1 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the…
- CVE-2026-63207 CVSS 6.9 medium Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored…
- CVE-2026-63206 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in…
- CVE-2026-63205 CVSS 5.1 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad…
- CVE-2026-63204 CVSS 2.3 low Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can…
- CVE-2026-63006 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets…
- CVE-2026-61855 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad's verification of…
- CVE-2026-84462 CVSS 8.6 high Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zammad's AI Agent…
- CVE-2026-65828 CVSS 2.3 low Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on…
- CVE-2026-61525 CVSS 8.8 high Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and…
- CVE-2026-56735 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer…
- CVE-2026-56734 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a…
- CVE-2026-56733 CVSS 8.7 high Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack of discursive…
- CVE-2026-56732 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows…
- CVE-2026-56731 CVSS 8.4 high Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject…
- CVE-2026-56730 CVSS 2.1 low Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that…
- CVE-2026-56728 CVSS 5.3 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerability exists in…
- CVE-2026-56727 CVSS 7.1 high Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP email processing, the…
- CVE-2026-56726 CVSS 5.1 medium Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation…
- CVE-2026-56725 CVSS 8.7 high Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request to POST…
- CVE-2026-56729 CVSS 2.1 low Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor…