{"id":"CVE-2026-63205","published":"2026-09-25T19:17:54.837","lastModified":"2026-09-29T20:17:21.623","description":"Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a new signature-owned record, without checking whether the user has permission to access the original attachment. The newly created copy is then downloadable by the same channel-admin user, because attachment access is determined by the copy's owner (the signature), not the original object (e.g., a ticket or knowledge-base article). This allows a user with any of the admin.channel_email, admin.channel_google, admin.channel_microsoft365, or admin.channel_microsoft_graph permissions to read attachments they would otherwise be denied access to, such as ticket attachments belonging to groups they are not a member of. This issue is fixed in version 7.1.2.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-639","CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/zammad/zammad/commit/f3e4da83621efad8443a4e9fe6bd87befad47c44","tags":[]},{"url":"https://github.com/zammad/zammad/security/advisories/GHSA-pp8r-x7pp-5qj5","tags":[]}],"exploitRefs":[{"url":"https://github.com/zammad/zammad/commit/f3e4da83621efad8443a4e9fe6bd87befad47c44","tags":[]},{"url":"https://github.com/zammad/zammad/security/advisories/GHSA-pp8r-x7pp-5qj5","tags":[]}],"hasPoc":true,"ai":null}