Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3918 articles · 228580 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-56732
zammad · zammad

Zammad: Malicious input in Ticket Body Enables Session Termination

Description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanitization allows injection of specific HTML elements into ticket bodies. When another user views the crafted ticket, the injected element can trigger a logout request, terminating the viewer's session. This vulnerability is fixed in 7.0.2.

Affected Products

VendorProductVersions
zammadzammad< 7.0.2

References

  • https://github.com/zammad/zammad/security/advisories/GHSA-6rmm-28j9-q99q(x_refsource_CONFIRM)
  • https://github.com/zammad/zammad/commit/3f6e8a5fa34eb0ce40f63292cf744f5f2992c9d0(x_refsource_MISC)
  • https://github.com/zammad/zammad/releases/tag/7.0.2(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB12d ago
CVE-2026-56732 | Zammad up to 7.0.1 HTML Sanitization input validation
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
CWECWE-20, CWE-352
PublishedSep 25, 2026
Trending Score7
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-102489
Undisclosed RCE in Zammad v6.3 and higher
Trending: 87
NONECVE-2026-102490
Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
Trending: 49
NONECVE-2026-56725
Zammad: Denial of Service via OTRS Import Controller
Trending: 8
NONECVE-2026-84458
Zammad: Account takeover via unverified email matching during SSO auto-link
Trending: 8
NONECVE-2026-61525
Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 25, 2026
Discovered by ZDM
Sep 25, 2026