Security Advisory Details

  • ID: ZAA-2026-05
  • Date: 2026-02-25
  • Title: Authorization Bypass Through User-Controlled Key
  • Severity: medium
  • Product: Zammad 6.5.x
  • Fixed in: Zammad 7.0.0
  • References:
    --> pending CVE assignment

Vulnerability Descriptions

Authorization Bypass Through User-Controlled Key

Authorized agent users were able to use the ticket_related endpoint to fetch asset data of arbitrary tickets, including customer and related user information. This is no longer the case.

Special 🙏 and 🤘 and ❤️ to:

For our SaaS customers, there’s nothing you need to worry about: we’ve already taken care of everything for you.

For self hosted installations, we strongly advise admins to update their system to the latest release of Zammad.

Fixed releases can be found at:

Or just update your Zammad if installed via OS package manager.

Additional information

Online version of this advisory: https://zammad.com/en/advisories/zaa-2026-05

Please see our security policy and send remarks on security issues exclusively to security@zammad.com.