Web-based Helpdesk System Vulnerability in Zammad by Zammad GmbH
CVE-2026-63216
5.3MEDIUM
What is CVE-2026-63216?
Zammad, an open-source helpdesk and customer support system, contains a vulnerability in its configuration dialogs for AI Agents that allows unsanitized option labels to be rendered as raw HTML. This flaw enables an attacker to inject harmful HTML and JavaScript into the system. Specifically, if an attacker can manipulate an option label—such as through a malicious user or organization name—they can craft a payload that executes in the browser of any administrator or agent accessing the affected configuration view. This critical issue has been addressed in version 7.1.2.
Affected Version(s)
zammad < 7.1.2
