CVE-2026-65828 | Zammad up to 7.1.1 AttachmentsController attachments_controller.rb AttachmentsController.destroy_form form_id privileges management
A vulnerability, which was classified as problematic, has been found in Zammad up to 7.1.1. This impacts the function AttachmentsController.destroy_form of the file app/controllers/attachments_controller.rb of the component AttachmentsController. Performing a manipulation of the argument form_id results in improper privilege management.
This vulnerability is reported as CVE-2026-65828. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More