CVE-2026-63204: Zammad: Authenticated agents can read AI summary error messages from inaccessible tickets
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI provider error message stored for that run, even if the run belongs to a ticket the agent is not authorized to access. The disclosure is limited to the provider error string; ticket content is not exposed. This issue is fixed in version 7.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.1.2
Event History
Frequently Asked Questions
Which users are realistically able to exploit this issue?
An attacker must be authenticated and have agent permissions in Zammad. They also need to submit an arbitrary AI analytics run identifier to the ticket summarize endpoint.
What information can be disclosed?
The issue exposes only the AI provider error message associated with the referenced analytics run. It does not expose the inaccessible ticket's content.
Are installations running the fixed release affected?
No. The issue is fixed in Zammad version 7.1.2; versions prior to 7.1.2 are affected under the described conditions.