CVE-2026-63205
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a new signature-owned record, without checking whether the user has permission to access the original attachment. The newly created copy is then downloadable by the same channel-admin user, because attachment access is determined by the copy's owner (the signature), not the original object (e.g., a ticket or knowledge-base article). This allows a user with any of the admin.channel_email, admin.channel_google, admin.channel_microsoft365, or admin.channel_microsoft_graph permissions to read attachments they would otherwise be denied access to, such as ticket attachments belonging to groups they are not a member of. This issue is fixed in version 7.1.2.
Weaknesses
CWE-639, CWE-862
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-52850PoC
- UNSCOREDCVE-2026-53626PoC
- UNSCOREDCVE-2026-56724PoC
- MEDIUMCVE-2026-61748PoC
- UNSCOREDCVE-2026-63204PoC
- MEDIUMCVE-2026-69190PoC
- HIGHCVE-2026-76087PoC
- HIGHCVE-2026-76089PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.