Unauthenticated Remote Access Vulnerability in Zammad Helpdesk System
CVE-2026-34723

8.7HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-34723?

Zammad, a web-based open source helpdesk and customer support system, had a critical flaw allowing unauthenticated remote attackers to access the 'getting started' endpoint. This access could lead to the exposure of sensitive internal entity data, even after the completion of system setup. The issue has been effectively resolved in versions 7.0.1 and 6.5.4, emphasizing the importance of keeping software up-to-date to safeguard against such vulnerabilities.

Affected Version(s)

zammad < 6.5.4 < 6.5.4

zammad >= 7.0.0-alpha, < 7.0.1 < 7.0.0-alpha, 7.0.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.