PT-2026-31421 · Zammad · Zammad

Published

2026-04-08

·

Updated

2026-04-09

·

CVE-2026-34724

CVSS v4.0

8.7

High

VectorAV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1
Description Zammad is a web-based open-source helpdesk/customer support system. A server-side template injection vulnerability exists via the AI Agent, potentially leading to Remote Code Execution (RCE). The impact is limited to environments where an attacker can control or influence the type enrichment data variable, typically within high-privilege administrative configurations. Approximately 5,400 systems are publicly indexed.
Recommendations Update to version 7.0.1 or later.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34724

Affected Products

Zammad