PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84460 zammad CVE debrief

CVE-2026-84460 is a vulnerability in Zammad, a web-based open-source helpdesk/customer support system. Prior to version 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for a given ticket, regardless of whether they have access to that ticket. This issue allows potential unauthorized access to sensitive tag information. The vulnerability is fixed in version 7.1.2. Defenders should assess exposure and prioritize patching to prevent exploitation.

Vendor
zammad
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Zammad instances should assess exposure and prioritize patching to prevent unauthorized access to sensitive tag information. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review official advisories for affected scope and severity and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Why it matters

CVE-2026-84460 allows authenticated users to access tag lists for tickets they do not have permission to view, potentially exposing sensitive information. Defenders should prioritize patching Zammad instances to version 7.1.2 or later.

  • Potential unauthorized access to sensitive tag information
  • Possible exposure of internal categorization features
  • Need for verification of Zammad instance vulnerability
  • Prioritization of patching to prevent exploitation

Technical summary

CVE-2026-84460 is a vulnerability in Zammad's REST endpoint for retrieving tag lists. An authenticated user can access tag names for a given ticket without having permission to view the ticket. This issue allows potential unauthorized access to sensitive tag information. The vulnerability is fixed in Zammad version 7.1.2. Defenders should prioritize patching Zammad instances to prevent unauthorized access to sensitive tag information. The issue is related to Zammad's internal categorization feature and may contain sensitive labels.

Defensive priority

Defenders should prioritize patching Zammad instances to prevent unauthorized access to sensitive tag information.

Recommended defensive actions

  • Patch Zammad instances to version 7.1.2 or later
  • Restrict access to sensitive tag information
  • Monitor for unauthorized access to ticket tags
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide information on the vulnerability, but details on exploitation or victim impact are not available. The issue is related to Zammad's REST endpoint for retrieving tag lists. The vulnerability was fixed in version 7.1.2. There is no information on known or unknown affected scope. Defenders should verify Zammad instance vulnerability and review official advisories for affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84460 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84460

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84460 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84460

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.