Authorization Bypass in Zammad Helpdesk System by Zammad
CVE-2026-34722

6.9MEDIUM

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-34722?

Zammad, an open-source helpdesk and customer support system, has a vulnerability that allows unauthorized ticket creation due to insufficient authorization on specific endpoints related to link addition. Versions prior to 7.0.1 and 6.5.4 are affected. This flaw can potentially enable attackers to manipulate ticket creation processes, leading to security breaches. The issue has been addressed in the releases 7.0.1 and 6.5.4, where appropriate authorization checks have been implemented.

Affected Version(s)

zammad < 6.5.4 < 6.5.4

zammad >= 7.0.0-alpha, < 7.0.1 < 7.0.0-alpha, 7.0.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.