PT-2026-31416 · Zammad · Zammad

Published

2026-04-08

·

Updated

2026-04-09

·

CVE-2026-34719

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1 and prior to 6.5.4
Description Zammad, a web-based open-source helpdesk/customer support system, had insufficient validation in its webhook model for loopback or link-local addresses. Only the URL scheme (HTTP/HTTPS) and hostname were checked, potentially allowing the retrieval of confidential metadata from cloud or hosting providers. The validation has been extended and is now applied during webhook configuration and job triggering.
Recommendations Update to Zammad version 7.0.1 or later. Update to Zammad version 6.5.4 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-34719

Affected Products

Zammad