Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal ticket isolation boundaries between agents. Any authenticated agent, even one with no active tickets assigned to them, can view the titles, status, labels, and URL links of GitHub/GitLab issues attached to any ticket in the system. This allows an internal user to systematically view GitHub/GitLab issue data linked by other agents or administrators across the organization by simply querying random or sequential ticket IDs. This vulnerability is fixed in 7.0.2. | |
| Title | Zammad: Missing authorization check in GitHub + GitLab integration allows cross-ticket data leak | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-25T17:01:00.957Z
Reserved: 2026-06-22T19:17:28.958Z
Link: CVE-2026-56726
No data.
Status : Received
Published: 2026-09-25T18:17:26.480
Modified: 2026-09-25T18:17:26.480
Link: CVE-2026-56726
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization