CVE-2026-77506: XSS
Published Aug 20, 2026
·Updated
Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.
Affected Software
1 affected component
Znuny<6.5.22
Event History
Aug 20, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs high privileges and user interaction. The vulnerable functionality is the AgentTicketEmailResend template.
2
Which deployments are affected?
Znuny versions before LTS 6.5.22 are affected. The provided information does not state whether the vulnerable template is enabled or used by default.