{"data":{"id":"14634e02-75a4-4352-a38e-388679f6e237","title":"CVE-2026-63204: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent per","summary":"Zammad, a web-based helpdesk system, has a security flaw in versions before 7.1.2 where an authenticated agent (a support staff member with permission to handle tickets) can trick the AI summarization feature into showing them error messages from AI providers even if they shouldn't have access to certain tickets. The leak is limited to error messages only, not the actual ticket information.","solution":"This issue is fixed in version 7.1.2.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63204","publishedAt":"2026-09-25T19:17:54.667Z","cveId":"CVE-2026-63204","cweIds":["CWE-639","CWE-862"],"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-25T19:17:54.667Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}