CVE-2026-63207: Zammad: Sensitive Information Exposure in Integration Administration API
Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses do not consistently mask sensitive fields, so configured secrets can be returned in plain text instead of the expected masked placeholder. Both the LDAP and Exchange integrations are affected. This issue is fixed in version 7.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zammadto a version that resolves this vulnerability.Fixed in 7.1.2
Event History
Frequently Asked Questions
Who can retrieve the exposed integration credentials?
An authenticated Zammad administrator can obtain them through the integration administration API. The issue is not described as exploitable by unauthenticated users.
Which integrations and versions are affected?
The affected integrations are LDAP and Exchange. The issue is identified in Zammad 7.0.3 and 7.1.1.
How can I determine whether credentials may have been exposed?
Review use of the integration administration API by authenticated administrators and determine whether LDAP or Exchange integrations were configured. In affected versions, API responses may return stored secrets in cleartext rather than a masked placeholder.
What is the remediation?
Upgrade to Zammad 7.1.2, which fixes the issue. If exposure is suspected, rotate the credentials configured for affected LDAP and Exchange integrations.