Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63216— Zammad: Stored XSS via unescaped option labels in the object attribute options context UI

Quick assessment

Affected
zammad zammad
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Zammad 是一个基于 Web 的开源帮助台/客户支持系统。在版本 7.1.2 之前,Zammad 的管理界面中 AI 代理的配置对话框会渲染未经验证和清理的选项标签。当渲染所选选项列表时,选项标签会未经转义地以原始 HTML 形式输出。攻击者若能控制某个选项标签(例如,通过在关系属性中设置恶意的用户名或组织名,或提供精心构造的自定义属性选项值),即可注入任意 HTML 和 JavaScript 代码。该恶意载荷将在任何打开受影响对象属性配置视图的管理员或代理的浏览器中执行。此问题已在 7.1.2 版本中得到修复

CVSS 5.3 · Medium EPSS 0.24% · P14

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 1

VendorProduct Version RangeStatus
zammad zammad < 7.1.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63216

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Zammad: Stored XSS via unescaped option labels in the object attribute options context UI
Source: CVE Program / CVE List V5
Vulnerability Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, the option label is output as raw HTML without escaping. An attacker who can control an option label, for example by setting a malicious string as a user or organization name used in a relation attribute, or by supplying a crafted custom attribute option value, can inject arbitrary HTML and JavaScript. The payload executes in the browser of any admin or agent who opens the affected object attribute configuration view. This issue is fixed in version 7.1.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zammad zammad < 7.1.2 -

II. Public POCs for CVE-2026-63216

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63216

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-63216 (1)

Vendor Advisories for CVE-2026-63216 (1)

Same Patch Batch · zammad · 2026-09-25 · 30 CVEs total

CVE-2026-84458 9.1 CRITICAL Zammad: Account takeover via unverified email matching during SSO auto-link
CVE-2026-61525 8.8 HIGH Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Control
CVE-2026-56733 8.7 HIGH Zammad: Incorrect Authorization and Improper Privilege Management
CVE-2026-56725 8.7 HIGH Zammad: Denial of Service via OTRS Import Controller
CVE-2026-84462 8.6 HIGH Zammad: AI Agent template sanitizer bypass leads to remote code execution
CVE-2026-56731 8.4 HIGH Zammad: Cross-Site Scripting in Ticket Notifications
CVE-2026-56724 7.1 HIGH Zammad: Incorrect implementation of permission checks in the knowledge base module
CVE-2026-56723 7.1 HIGH Zammad: Missing authorization on ticket attachment download
CVE-2026-56727 7.1 HIGH Zammad: PGP signature spoofing via unvalidated verification return
CVE-2026-84465 7.1 HIGH Zammad: S/MIME signature verification allows forged sender impersonation
CVE-2026-84464 7.1 HIGH Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organizati
CVE-2026-84461 6.9 MEDIUM Zammad: Missing rate limiting allows password brute-forcing during two-factor login
CVE-2026-63207 6.9 MEDIUM Zammad: Sensitive Information Exposure in Integration Administration API
CVE-2026-84463 6.3 MEDIUM Zammad: Stored HTML injection in Knowledge Base video widget enables forced session switch
CVE-2026-84460 5.3 MEDIUM Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag Enumeration
CVE-2026-56728 5.3 MEDIUM Zammad: Cross-User Taskbar Item Access Control Vulnerability
CVE-2026-56735 5.3 MEDIUM Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad
CVE-2026-56732 5.3 MEDIUM Zammad: Malicious input in Ticket Body Enables Session Termination
CVE-2026-56734 5.3 MEDIUM Zammad: Avatar Image URL Server-Side Request Forwarding
CVE-2026-63206 5.3 MEDIUM Zammad: Remote image tracking bypass via shortened URL scheme

Showing top 20 of 30 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-63216

No comments yet


Leave a comment