CVE-2026-63208: Zammad: Microsoft Graph error logs expose partially masked OAuth access tokens

Published Sep 25, 2026
·
Updated

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide this token in the log, but the masking is incomplete: for the token format Microsoft uses (JWT), only the first part is hidden, while the remaining parts remain readable in plain text. A Zammad admin with Microsoft Graph channel access can view these logs and see the partial token, which may reveal sensitive claims such as the account scope, tenant, or timing, and could assist in reconstructing the full token while it is still valid. This issue is fixed in version 7.1.2.

Affected Software

1 affected component
Zammad Zammad<7.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Zammad to a version that resolves this vulnerability.

    Fixed in 7.1.2

Event History

Sep 25, 2026
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can view the exposed token material?

A Zammad administrator with access to the Microsoft Graph channel can view the affected error logs. The issue is relevant where Microsoft Graph mailbox requests fail and their errors are logged.

2

What information remains visible despite masking?

For Microsoft JWT access tokens, only the first part is hidden. The remaining token parts can remain readable in plain text and may reveal claims such as account scope, tenant, or timing.

3

Which versions are affected and what is the remediation?

Versions prior to 7.1.2 are affected. Upgrade Zammad to version 7.1.2.

4

How can an organization determine whether it may have been exposed?

Review Microsoft Graph request error logs accessible to Zammad administrators for partially masked JWT token values. Exposure is possible when failed Microsoft Graph requests caused these errors to be logged.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203