๐Ÿ” CVE Alert

CVE-2026-63205

UNKNOWN 0.0

Zammad: Channel admins can read unauthorized attachments via signature rich-text body

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a new signature-owned record, without checking whether the user has permission to access the original attachment. The newly created copy is then downloadable by the same channel-admin user, because attachment access is determined by the copy's owner (the signature), not the original object (e.g., a ticket or knowledge-base article). This allows a user with any of the admin.channel_email, admin.channel_google, admin.channel_microsoft365, or admin.channel_microsoft_graph permissions to read attachments they would otherwise be denied access to, such as ticket attachments belonging to groups they are not a member of. This issue is fixed in version 7.1.2.

CWE CWE-639 CWE-862
Vendor zammad
Product zammad
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for zammad zammad

Be the first to know when new unknown vulnerabilities affecting zammad zammad are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zammad / zammad
< 7.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zammad/zammad/security/advisories/GHSA-pp8r-x7pp-5qj5 github.com: https://github.com/zammad/zammad/commit/f3e4da83621efad8443a4e9fe6bd87befad47c44