CVE-2026-34718: Zammad improperly neutralizes of script-related HTML tags in ticket articles
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for ticket articles was missing proper sanitization of data: ... URI schemes, resulting in storing such malicious content in the database of the Zammad instance. The Zammad GUI is rendering this content, due to applied CSP rules no harm was done by e.g., clicking such a link. This vulnerability is fixed in 7.0.1 and 6.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.1 - Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 6.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34718?
CVE-2026-34718 is classified as a high severity vulnerability due to its potential for script injection attacks.
How can I fix CVE-2026-34718?
To mitigate CVE-2026-34718, update Zammad to version 7.0.1 or 6.5.4 or later.
What is the impact of CVE-2026-34718 on affected systems?
CVE-2026-34718 can allow attackers to execute arbitrary scripts stored in ticket articles, compromising user data.
Which versions of Zammad are affected by CVE-2026-34718?
CVE-2026-34718 affects Zammad versions prior to 7.0.1 and 6.5.4.
Is user data at risk due to CVE-2026-34718?
Yes, user data may be at risk as CVE-2026-34718 allows for possible data manipulation and script execution.