Bypass of HTML Sanitizer in Zammad Open Source Helpdesk System
CVE-2026-63206

5.3MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-63206?

Zammad, a web-based open-source helpdesk system, has a vulnerability that allows attackers to bypass its HTML sanitizer. Earlier versions than 7.1.2 are affected, as the sanitizer fails to identify shortened URL formats without the typical double slash after the scheme. This flaw permits remote images to be loaded silently during ticket viewing or email interaction, effectively revealing ticket activity and potentially sensitive user information. This risk exposes users to unintentional data leaks without the usual warning of blocked remote content. The issue was resolved in version 7.1.2.

Affected Version(s)

zammad < 7.1.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.