Multiple vulnerabilities in the Zammad helpdesk and ticketing system (CVSS Base Score 8.8) can be exploited remotely by an attacker to gain administrator privileges, bypass security measures, manipulate data, disclose sensitive information, or cause a denial-of-service condition. Affected versions are Zammad versions prior to 7.0.2 and versions prior to 7.1. A patch or mitigation is available, but the article does not specify the exact fixed version number to upgrade to.
[WID-SEC-2026-1981] Zammad: Mehrere Schwachstellen CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 16.06.2026 Stand 17.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Zammad ist ein Helpdesk- und Ticketsystem. Produkte 16.06.2026 Zammad Zammad <7.1 Zammad Zammad <7.0.2 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Zammad ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen. CVE Informationen Versionshistorie Feedback zum Advisory geben