CVE-2026-63205
Last modified
CVE-2026-63205 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body.
Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a new signature-owned record, without checking whether the user has permission to access the original attachment. The newly created copy is then downloadable by the same channel-admin user, because attachment access is determined by the copy's owner (the signature), not the original object (e.g., a ticket or knowledge-base article). This allows a user with any of the admin.channel_email, admin.channel_google, admin.channel_microsoft365, or admin.channel_microsoft_graph permissions to read attachments they would otherwise be denied access to, such as ticket attachments belonging to groups they are not a member of. This issue is fixed in version 7.1.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zammad | zammad | < 7.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-63205?
How severe is CVE-2026-63205?
How do I fix CVE-2026-63205?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63188Logto is the modern, open-source auth infrastructure for Saa…8.7
- CVE-2026-6319Use after free in Payments in Google Chrome on Android prior…7.5
- CVE-2026-63199Perses is an open-source dashboard and visualization project…8.3
- CVE-2026-6320The Salon Booking System – Free Version plugin for WordPress…7.5
- CVE-2026-63203Logto is the modern, open-source auth infrastructure for Saa…7.6
- CVE-2026-63204Zammad is a web based open source helpdesk/customer support …2.3
- CVE-2026-63206Zammad is a web based open source helpdesk/customer support …5.3
- CVE-2026-63207Zammad is a web based open source helpdesk/customer support …6.9
- CVE-2026-63208Zammad is a web based open source helpdesk/customer support …5.1
- CVE-2026-6321fast-uri decoded percent-encoded path separators and dot seg…7.5
- CVE-2026-63216Zammad is a web based open source helpdesk/customer support …5.3
- CVE-2026-63219GeoNetwork is a catalog application to manage spatially refe…8.6
Are you affected by CVE-2026-63205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
