PT-2026-31423 · Zammad · Zammad

Published

2026-04-08

·

Updated

2026-04-09

·

CVE-2026-34782

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1 and prior to 6.5.4
Description Zammad, a web-based open source helpdesk system, had an issue where the REST endpoint ''/api/v1/ai assistance/text tools/:id'' did not verify user privileges for using text tools. This allowed unauthorized access to these tools in all scenarios. The id variable in the API endpoint was not properly validated.
Recommendations Upgrade to Zammad version 7.0.1 or later. Upgrade to Zammad version 6.5.4 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-34782

Affected Products

Zammad