CVE-2026-65828
Zammad: Pending upload deletion bypass via legacy attachment endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on AttachmentsController deletes UploadCache Store records based solely on a user-supplied form_id without verifying that the requesting user owns those records. An authenticated attacker who learns another user's pending-upload UUID can silently remove temporary file uploads before the victim submits their ticket or article. This issue is fixed in version 7.1.2.
| CWE | CWE-862 |
| Vendor | zammad |
| Product | zammad |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for zammad zammad
Be the first to know when new unknown vulnerabilities affecting zammad zammad are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
zammad / zammad
< 7.1.2