Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3921 articles · 228597 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-61525
zammad · zammad

Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller

Description

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are insufficiently validated before being used to construct internal file paths. When the file-based session store is active (the default configuration), an authenticated attacker can manipulate the session identifier to reference locations outside the intended storage directory, leading to the deletion of arbitrary files and directories on the server. Exploitation requires only a low-privilege authenticated session and a single crafted request. Instances configured to use the Redis-based session store are not affected. This issue is fixed in versions 7.0.3 and 7.1.1.

Affected Products

VendorProductVersions
zammadzammad= 7.0.2, = 7.1.0

References

  • https://github.com/zammad/zammad/security/advisories/GHSA-xp9w-hhf3-vfxx(x_refsource_CONFIRM)
  • https://github.com/zammad/zammad/commit/cf3425712e8fae1bd40fa5814a49dc318dc84006(x_refsource_MISC)
  • https://github.com/zammad/zammad/commit/f78ef2434fd8aad6c2fb8a702788f6e3f33565f6(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB12d ago
CVE-2026-61525 | Zammad 7.0.2/7.1.0 Session Management path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
CWECWE-22
PublishedSep 25, 2026
Trending Score8
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-102489
Undisclosed RCE in Zammad v6.3 and higher
Trending: 87
NONECVE-2026-102490
Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
Trending: 49
NONECVE-2026-56725
Zammad: Denial of Service via OTRS Import Controller
Trending: 8
NONECVE-2026-84458
Zammad: Account takeover via unverified email matching during SSO auto-link
Trending: 8
NONECVE-2026-56732
Zammad: Malicious input in Ticket Body Enables Session Termination
Trending: 7

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 25, 2026
Discovered by ZDM
Sep 25, 2026