Vulnerability in Zammad Web-Based Helpdesk System Allows File Deletion by Unauthorized Users
CVE-2026-65828

2.3LOW

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-65828?

Zammad, a widely used open source helpdesk and customer support system, has a vulnerability in its AttachmentsController. Specifically, prior to version 7.1.2, a flaw in the destroy_form action allows an authenticated user to delete temporary file uploads associated with another user, as it relies solely on a user-supplied form_id without proper ownership verification. An attacker who discovers another user’s pending-upload UUID can exploit this to remove essential files before the original user can submit their support ticket or article. This alarming exposure highlights the need for robust user validation within the system. The issue has been resolved in version 7.1.2.

Affected Version(s)

zammad < 7.1.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.