Junglewise Threat Intelligence

CVE-2026-77506: Znuny AgentTicketEmailResend template XSS

CVE-2026-77506 · Severity: medium · CVSS 4.8 · Published 2026-08-20

Technologies: Znuny, Znuny LTS. Vendors: Znuny.

Executive brief

Znuny is an open-source help desk and IT service management platform used by organizations to manage customer support tickets. A cross-site scripting (XSS) vulnerability in the agent ticket email resend feature allows an authenticated agent to inject malicious code that would execute in other agents' browsers, potentially leading to unauthorized actions, credential theft, or account takeover.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the AgentTicketEmailResend template within Znuny's agent interface. The vulnerability arises from user-controlled data being rendered without proper HTML output encoding, allowing an authenticated agent to inject arbitrary HTML or JavaScript code. The attack requires an agent with access to the agent interface (authenticated attack) and relies on social engineering or user interaction to trick another agent into viewing a malicious email resend payload. An attacker can execute arbitrary JavaScript in the victim agent's browser session within the Znuny domain, potentially compromising the victim's account or stealing session tokens. Znuny LTS 6.5.22 and later versions contain the fix.

Affected products

  • Znuny Znuny LTS 6.5.1 to 6.5.21
  • Znuny Znuny 6.0, 6.1, 6.2, 6.3, 6.4

Timeline

  • 2026-06-24: disclosed
  • 2026-08-20: patched: Fixed in Znuny LTS 6.5.22

References

Related threats