Bypass of HTML Sanitizer in Zammad Open Source Helpdesk System
CVE-2026-63206
5.3MEDIUM
What is CVE-2026-63206?
Zammad, a web-based open-source helpdesk system, has a vulnerability that allows attackers to bypass its HTML sanitizer. Earlier versions than 7.1.2 are affected, as the sanitizer fails to identify shortened URL formats without the typical double slash after the scheme. This flaw permits remote images to be loaded silently during ticket viewing or email interaction, effectively revealing ticket activity and potentially sensitive user information. This risk exposes users to unintentional data leaks without the usual warning of blocked remote content. The issue was resolved in version 7.1.2.
Affected Version(s)
zammad < 7.1.2
