Security Advisory Details

  • ID: ZAA-2026-06
  • Date: 2026-03-04
  • Title: SQL Injection
  • Severity: critical
  • Product: Zammad 6.5.x
  • Fixed in: Zammad 7.0.0
  • References:
    --> pending CVE assignment

Vulnerability Descriptions

SQL Injection

Due to improper SQL statement sanitization, authorized agent or customer users were able to use several API endpoints to inject custom statements to SQL queries. This could lead to the execution of unwanted operations on database level.

Special 🙏 and 🤘 and ❤️:

This issue was discovered with the GitHub Security Lab Taskflow Agent and manually verified by GHSL team members @p- (Peter Stöckli) and @m-y-mo (Man Yue Mo)

For our SaaS customers, there’s nothing you need to worry about: we’ve already taken care of everything for you.

For self hosted installations, we strongly advise admins to update their system to the latest release of Zammad.

Fixed releases can be found at:

Or just update your Zammad if installed via OS package manager.

Additional information

Online version of this advisory: https://zammad.com/en/advisories/zaa-2026-06

Please see our security policy and send remarks on security issues exclusively to security@zammad.com.