SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77506

MEDIUM · CVSS 4.8 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Znuny versions prior to LTS 6.5.22 are vulnerable to a cross-site scripting (XSS) flaw in the AgentTicketEmailResend template, which could allow attackers to inject malicious scripts into the application. This vulnerability poses a medium risk as it could lead to unauthorized actions or data exposure for users interacting with affected email templates. Organizations using Znuny should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-77506
Severity
MEDIUM
CVSS
4.8
EPSS
0.25%

Original NVD Description

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.