OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-56731

HIGH · CVSS 8.4 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in Zammad prior to version 7.0.1 allows low-privilege authenticated users to inject arbitrary HTML and JavaScript into ticket titles during the creation process, as the input is not properly sanitized. This could lead to cross-site scripting (XSS) attacks, potentially compromising user data and system integrity. Organizations using Zammad should prioritize upgrading to version 7.0.1 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56731
Severity
HIGH
CVSS
8.4
EPSS
0.24%
Java

Original NVD Description

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user may inject arbitrary HTML markup, including JavaScript event handlers, into a ticket title via the standard ticket creation workflow. The title is persisted without sanitization. This issue is fixed in version 7.0.1.