Junglewise Threat Intelligence

CVE-2026-34718: Zammad HTML sanitizer XSS in ticket articles

CVE-2026-34718 · Severity: medium · CVSS 6.1 · Published 2026-04-08

Technologies: Zammad. Vendors: Zammad.

Executive brief

Zammad is an open-source customer support and helpdesk platform. A security flaw in how the system handles ticket content allowed malicious links or scripts to be stored in the database. While existing security measures prevented immediate harm, an attacker could potentially use this to display unauthorized content to support agents.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Zammad due to improper neutralization of script-related HTML tags and URI schemes in ticket articles. The HTML sanitizer failed to properly validate input, allowing malicious payloads to be persisted in the database. When an agent views the affected ticket, the Zammad GUI renders this content. Although the impact was mitigated by existing Content Security Policy (CSP) rules, the flaw allowed for the storage and rendering of unauthorized URI schemes. The issue is resolved in versions 7.0.1 and 6.5.4.

Affected products

  • Zammad Zammad < 6.5.4, >= 7.0.0-alpha < 7.0.1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats