CVE-2026-56729: Zammad: Titles of knowledge base answers will be shown across all categories via the global search
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledgebase.editor in one category can see answer titles and updatedat timestamps from categories they do not have editor access to , via the global quick search. Category names are not leaked, and opening the answer returns "Page not found," but the title alone may disclose sensitive information. This vulnerability is fixed in 7.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.0.2
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who has the knowledge_base.editor role in at least one knowledge base category can use global quick search to view answer titles and updated_at timestamps from categories where they do not have editor access.
What information is exposed, and can the restricted answers be opened?
The global quick search can expose titles and updated_at timestamps of restricted-category answers. Category names are not leaked, and attempting to open an inaccessible answer returns "Page not found."
Which versions are affected and what is the fix?
Zammad versions prior to 7.0.2 are affected. Upgrade to version 7.0.2, which fixes the issue.