Executive brief
Zammad is an open-source helpdesk and customer support platform. A security flaw allowed customers within 'shared organizations' to view internal ticket data that should have been hidden, such as ticket priority levels and internal administrative notes. While unauthorized users could see this sensitive information when viewing tickets from other members of their organization, they were not able to modify the data.
Technical details
An improper access control vulnerability (CWE-284) exists in Zammad's ticket detail view for shared organizations. When a customer user opens a ticket belonging to another user within the same shared organization, the system fails to filter internal-only fields. This results in the disclosure of sensitive attributes such as ticket priority and custom internal ticket attributes. The attack requires low privileges (a valid customer account within a shared organization) and some user interaction. The vulnerability is limited to information disclosure as affected users cannot modify the exposed fields. The issue is resolved in version 7.0.1.
Affected products
- Zammad Zammad >= 7.0.0, < 7.0.1
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched: Fixed in version 7.0.1