CVE-2026-63207
Received Received - Intake

Stored Integration Credentials Exposure in Zammad

Vulnerability report for CVE-2026-63207, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses do not consistently mask sensitive fields, so configured secrets can be returned in plain text instead of the expected masked placeholder. Both the LDAP and Exchange integrations are affected. This issue is fixed in version 7.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
zammad zammad 7.1.2
zammad zammad From 7.0.3 (inc) to 7.1.2 (exc)
zammad zammad From 7.1.1 (inc) to 7.1.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zammad versions 7.0.3 and 7.1.1 have a vulnerability where an authenticated administrator can retrieve stored integration credentials in plain text through the integration administration API. This happens because certain responses do not consistently mask sensitive fields, exposing configured secrets instead of a masked placeholder. Both LDAP and Exchange integrations are affected.

Impact Analysis

An attacker with administrator access could exploit this to steal plaintext credentials for LDAP or Exchange integrations. This could lead to unauthorized access to user data, internal systems, or further network compromise depending on the integration's permissions.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR (data protection) or HIPAA (health information security) by exposing sensitive credentials and potentially allowing unauthorized access to personal or protected health data. Organizations using affected versions may face regulatory penalties or audit failures.

Mitigation Strategies

Upgrade Zammad to version 7.1.2 or later to address the issue where sensitive integration credentials are exposed in cleartext.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63207. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart