HTML Injection Vulnerability in Zammad Helpdesk System
CVE-2026-84463
6.3MEDIUM
What is CVE-2026-84463?
Zammad, an open-source web-based helpdesk and customer support system, is susceptible to an HTML injection vulnerability. Users with editing rights in the Knowledge Base can craft a response that embeds malicious HTML into a published answer. This unescaped content compromises the page's HTML context, allowing attackers to inject additional code. Consequently, when another authorized user views this answer, their browser inadvertently submits a request to Zammad’s session-switching endpoint using their active credentials, potentially hijacking their user session. This issue has been remediated in version 7.1.2 of the product.
Affected Version(s)
zammad < 7.1.2
