CVE-2026-61525

Source
https://cve.org/CVERecord?id=CVE-2026-61525
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61525.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-61525
Aliases
  • GHSA-xp9w-hhf3-vfxx
Published
2026-09-25T17:11:33Z
Modified
2026-09-27T03:47:26Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller
Details

Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for websocket and long-polling connections is susceptible to a path traversal attack. Session identifiers supplied by the client are insufficiently validated before being used to construct internal file paths. When the file-based session store is active (the default configuration), an authenticated attacker can manipulate the session identifier to reference locations outside the intended storage directory, leading to the deletion of arbitrary files and directories on the server. Exploitation requires only a low-privilege authenticated session and a single crafted request. Instances configured to use the Redis-based session store are not affected. This issue is fixed in versions 7.0.3 and 7.1.1.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-22"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61525.json"
}
References

Affected packages

Git / github.com/zammad/zammad

Affected ranges

Type
GIT
Repo
https://github.com/zammad/zammad
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "= 7.0.2"
        },
        {
            "last_affected":  "= 7.0.2"
        },
        {
            "introduced":  "= 7.1.0"
        },
        {
            "last_affected":  "= 7.1.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

7.*
7.0.2
= 7.*
= 7.0.2
= 7.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61525.json"