CyberRota Analysis
AI-GeneratedZnuny versions prior to LTS 6.5.22 are vulnerable to a cross-site scripting (XSS) flaw in the AgentTicketEmailResend template, which could allow attackers to inject malicious scripts into the application. This vulnerability poses a medium risk as it could lead to unauthorized actions or data exposure for users interacting with affected email templates. Organizations using Znuny should prioritize patching to mitigate potential exploitation risks.
CVE
CVE-2026-77506
Severity
MEDIUM
CVSS
4.8
EPSS
0.25%
Original NVD Description
Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.