PT-2026-31420 · Zammad · Zammad

CVE-2026-34723

·

Published

2026-04-08

·

Updated

2026-04-09

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1 and prior to 6.5.4
Description Zammad, a web-based open-source helpdesk system, allowed unauthenticated remote attackers to access sensitive internal entity data through the getting started endpoint, even after initial system setup. This access was possible in versions before 7.0.1 and 6.5.4.
Recommendations Update to version 7.0.1 or later. Update to version 6.5.4 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34723
GHSA-HCM9-CH62-5727

Affected Products

Zammad