PT-2026-31420 · Zammad · Zammad

Published

2026-04-08

·

Updated

2026-04-09

·

CVE-2026-34723

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1 and prior to 6.5.4
Description Zammad, a web-based open-source helpdesk system, allowed unauthenticated remote attackers to access sensitive internal entity data through the getting started endpoint, even after initial system setup. This access was possible in versions before 7.0.1 and 6.5.4.
Recommendations Update to version 7.0.1 or later. Update to version 6.5.4 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-34723

Affected Products

Zammad