Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledge_base.editor in one category can see answer titles and updated_at timestamps from categories they do not have editor access to , via the global quick search. Category names are not leaked, and opening the answer returns "Page not found," but the title alone may disclose sensitive information. This vulnerability is fixed in 7.0.2. | |
| Title | Zammad: Titles of knowledge base answers will be shown across all categories via the global search | |
| Weaknesses | CWE-200 CWE-280 CWE-284 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-25T17:09:29.330Z
Reserved: 2026-06-22T19:17:28.959Z
Link: CVE-2026-56729
No data.
Status : Received
Published: 2026-09-25T17:17:09.557
Modified: 2026-09-25T18:17:26.943
Link: CVE-2026-56729
No data.
OpenCVE Enrichment
No data.