๐Ÿ” CVE Alert

CVE-2026-61525

UNKNOWN 0.0

Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are insufficiently validated before being used to construct internal file paths. When the file-based session store is active (the default configuration), an authenticated attacker can manipulate the session identifier to reference locations outside the intended storage directory, leading to the deletion of arbitrary files and directories on the server. Exploitation requires only a low-privilege authenticated session and a single crafted request. Instances configured to use the Redis-based session store are not affected. This issue is fixed in versions 7.0.3 and 7.1.1.

CWE CWE-22
Vendor zammad
Product zammad
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for zammad zammad

Be the first to know when new unknown vulnerabilities affecting zammad zammad are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zammad / zammad
= 7.0.2 = 7.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zammad/zammad/security/advisories/GHSA-xp9w-hhf3-vfxx github.com: https://github.com/zammad/zammad/commit/cf3425712e8fae1bd40fa5814a49dc318dc84006 github.com: https://github.com/zammad/zammad/commit/f78ef2434fd8aad6c2fb8a702788f6e3f33565f6