CVE-2026-63204: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent per
Summary
Zammad, a web-based helpdesk system, has a security flaw in versions before 7.1.2 where an authenticated agent (a support staff member with permission to handle tickets) can trick the AI summarization feature into showing them error messages from AI providers even if they shouldn't have access to certain tickets. The leak is limited to error messages only, not the actual ticket information.
Solution / Mitigation
This issue is fixed in version 7.1.2.
Vulnerability Details
EPSS: 0.0%
September 25, 2026
Classification
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63204
First tracked: September 25, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 75%