Why teams of all sizes choose Zammad for structured, reliable support.
ZAA-2026-04
· Please read carefully and check if the version of your Zammad system is affected by this vulnerability. Please send us information regarding vulnerabilities in Zammad!
Security Advisory Details
- ID: ZAA-2026-04
- Date: 2026-02-25
- Title: Exposure of Sensitive Information to an Unauthorized Actor
- Severity: medium
- Product: Zammad 6.5.x
- Fixed in: Zammad 7.0.0 & 6.5.3
- References:
--> pending CVE assignment
Vulnerability Descriptions
Exposure of Sensitive Information to an Unauthorized Actor
Unauthorized users were able to use the API to get information about internal import status metadata. This is no longer possible.
Special 🙏 and 🤘 and ❤️ to:
- N: Sho Odagiri
- C: GMO Cybersecurity
- W: https://gmo-cybersecurity.com/
Recommended Resolution
For our SaaS customers, there’s nothing you need to worry about: we’ve already taken care of everything for you.
For self hosted installations, we strongly advise admins to update their system to the latest release of Zammad.
Fixed releases can be found at:
Or just update your Zammad if installed via OS package manager.
Additional information
Online version of this advisory: https://zammad.com/en/advisories/zaa-2026-04
Please see our security policy and send remarks on security issues exclusively to security@zammad.com.