CVE-2026-63216: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are render
Summary
Zammad, a web-based helpdesk system, has a vulnerability in versions before 7.1.2 where option labels in AI Agent configuration dialogs are not properly sanitized (cleaned of malicious code). An attacker can inject malicious HTML and JavaScript by controlling an option label, such as through a user name or custom attribute, and this malicious code runs in the browser of any admin or agent who views the affected configuration. This is a type of code injection attack where unsafe user input is directly displayed without protection.
Solution / Mitigation
Update to version 7.1.2 or later, where this issue is fixed.
Vulnerability Details
EPSS: 0.0%
September 25, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63216
First tracked: September 25, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 85%