Data Exposure Risk in Zammad Helpdesk System
CVE-2026-84464
7.1HIGH
What is CVE-2026-84464?
Zammad, an open-source web-based helpdesk solution, had a significant vulnerability in its External Data Source feature prior to version 7.1.2. This flaw allowed authenticated users, even those with basic access, to exploit the system by referencing unauthorized record IDs. Consequently, such users could inadvertently gain access to sensitive information related to tickets, customer accounts, and organizational data that were not meant for their view. The issue has been resolved in version 7.1.2, emphasizing the importance of proper access controls in safeguarding sensitive information.
Affected Version(s)
zammad < 7.1.2
