CVE-2026-84460
Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for the given ticket, regardless of whether they have access to that ticket. Tags are an internal categorization feature and may contain sensitive labels. Ticket IDs are sequential integers, making bulk enumeration straightforward. This issue is fixed in version 7.1.2.
| CWE | CWE-639 |
| Vendor | zammad |
| Product | zammad |
| Published | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for zammad zammad
Be the first to know when new unknown vulnerabilities affecting zammad zammad are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
zammad / zammad
< 7.1.2