HTML Injection Vulnerability in Zammad Helpdesk System
CVE-2026-84463

6.3MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-84463?

Zammad, an open-source web-based helpdesk and customer support system, is susceptible to an HTML injection vulnerability. Users with editing rights in the Knowledge Base can craft a response that embeds malicious HTML into a published answer. This unescaped content compromises the page's HTML context, allowing attackers to inject additional code. Consequently, when another authorized user views this answer, their browser inadvertently submits a request to Zammad’s session-switching endpoint using their active credentials, potentially hijacking their user session. This issue has been remediated in version 7.1.2 of the product.

Affected Version(s)

zammad < 7.1.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.