Cross-Site Scripting Flaw in Zammad Helpdesk System
CVE-2026-56731

8.4HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-56731?

Zammad, an open-source web-based helpdesk and customer support system, is susceptible to a cross-site scripting vulnerability. In versions prior to 7.0.1, a low-privilege authenticated user can exploit the system by injecting arbitrary HTML markup and JavaScript event handlers into ticket titles during the ticket creation process. This injection occurs because the title is stored without proper sanitization, allowing malicious scripts to execute when other users view the ticket. The vulnerability has been addressed in version 7.0.1, emphasizing the importance of keeping software up to date to maintain security.

Affected Version(s)

zammad < 7.0.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.