Low severityNVD Advisory· Published Sep 25, 2026
CVE-2026-63204
CVE-2026-63204
Description
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent permissions can supply an arbitrary AI analytics run identifier to the ticket summarize endpoint and receive the AI provider error message stored for that run, even if the run belongs to a ticket the agent is not authorized to access. The disclosure is limited to the provider error string; ticket content is not exposed. This issue is fixed in version 7.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
1- Zammad: 25 Vulnerabilities Disclosed, Including Critical Flaw in SSO AuthenticationVypr Intelligence · Sep 25, 2026