HTML Sanitization Flaw in Zammad Helpdesk System Exposes User Data
CVE-2026-56735

5.3MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-56735?

Zammad, an open-source helpdesk and customer support system, has a vulnerability in its HTML sanitizer that allows attackers to embed malicious external URLs in the srcset attribute of tags. Despite blocking external URLs in the standard implementation, the srcset attribute was overlooked, leading to potential exposure of user data, including IP addresses and referral information, when agents interact with affected emails. The issue has been addressed in subsequent releases, specifically versions 7.0.2 and 7.1.0, which enhance the sanitizer to prevent unauthorized external content from compromising user privacy.

Affected Version(s)

zammad < 7.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.