CVE-2026-56731: Zammad
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket creation workflow. The title is persisted without sanitization. This issue is fixed in version 7.0.1.
Affected products
- Zammad Zammad: before 7.0.1 (fixed in 7.0.1)
Published 2026-09-25. Last modified 2026-09-28.