Authorization Bypass in Zammad Helpdesk System by Zammad
CVE-2026-34722
6.9MEDIUM
What is CVE-2026-34722?
Zammad, an open-source helpdesk and customer support system, has a vulnerability that allows unauthorized ticket creation due to insufficient authorization on specific endpoints related to link addition. Versions prior to 7.0.1 and 6.5.4 are affected. This flaw can potentially enable attackers to manipulate ticket creation processes, leading to security breaches. The issue has been addressed in the releases 7.0.1 and 6.5.4, where appropriate authorization checks have been implemented.
Affected Version(s)
zammad < 6.5.4 < 6.5.4
zammad >= 7.0.0-alpha, < 7.0.1 < 7.0.0-alpha, 7.0.1
