Path Traversal Attack on Zammad Helpdesk System by Zammad
CVE-2026-61525

8.8HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-61525?

Zammad, a popular open-source helpdesk and customer support system, is vulnerable due to its session management for websocket and long-polling connections. In versions 7.0.2 and 7.1.0, improper validation of session identifiers allows an authenticated attacker to exploit this flaw, conducting a path traversal attack that can reference file locations outside the designated storage space. This can lead to unauthorized deletion of files on the server, given that the default file-based session storage is being utilized. Fortunately, the vulnerability has been addressed in subsequent releases, 7.0.3 and 7.1.1, which mitigate these risks effectively.

Affected Version(s)

zammad = 7.0.2 = 7.0.2

zammad = 7.1.0 = 7.1.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.