Cross-Site Scripting Flaw in Zammad Helpdesk System
CVE-2026-56731
8.4HIGH
What is CVE-2026-56731?
Zammad, an open-source web-based helpdesk and customer support system, is susceptible to a cross-site scripting vulnerability. In versions prior to 7.0.1, a low-privilege authenticated user can exploit the system by injecting arbitrary HTML markup and JavaScript event handlers into ticket titles during the ticket creation process. This injection occurs because the title is stored without proper sanitization, allowing malicious scripts to execute when other users view the ticket. The vulnerability has been addressed in version 7.0.1, emphasizing the importance of keeping software up to date to maintain security.
Affected Version(s)
zammad < 7.0.1
