Path Traversal Vulnerability in Zammad Helpdesk System
CVE-2026-63006
5.3MEDIUM
What is CVE-2026-63006?
The Zammad Helpdesk system has a path traversal vulnerability that allows an attacker to bypass the image URL sanitizer. This occurs when HTML content from inbound emails or tickets includes crafted URL paths. When authenticated agents access this content, the compromised URLs can interact with protected API endpoints, potentially leading to unexpected actions such as forced logouts without any user intervention. The issue has been remedied in version 7.1.2 to enhance security and protect against such attacks.
Affected Version(s)
zammad < 7.1.2
