Data Exposure Risk in Zammad Helpdesk System
CVE-2026-84464

7.1HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-84464?

Zammad, an open-source web-based helpdesk solution, had a significant vulnerability in its External Data Source feature prior to version 7.1.2. This flaw allowed authenticated users, even those with basic access, to exploit the system by referencing unauthorized record IDs. Consequently, such users could inadvertently gain access to sensitive information related to tickets, customer accounts, and organizational data that were not meant for their view. The issue has been resolved in version 7.1.2, emphasizing the importance of proper access controls in safeguarding sensitive information.

Affected Version(s)

zammad < 7.1.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.