Vulnerability in Zammad Web-Based Helpdesk System Allows File Deletion by Unauthorized Users
CVE-2026-65828
2.3LOW
What is CVE-2026-65828?
Zammad, a widely used open source helpdesk and customer support system, has a vulnerability in its AttachmentsController. Specifically, prior to version 7.1.2, a flaw in the destroy_form action allows an authenticated user to delete temporary file uploads associated with another user, as it relies solely on a user-supplied form_id without proper ownership verification. An attacker who discovers another user’s pending-upload UUID can exploit this to remove essential files before the original user can submit their support ticket or article. This alarming exposure highlights the need for robust user validation within the system. The issue has been resolved in version 7.1.2.
Affected Version(s)
zammad < 7.1.2
