Server-Side Template Injection in Zammad Helpdesk System
CVE-2026-34724

8.7HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-34724?

CVE-2026-34724 is a server-side template injection vulnerability found in the Zammad Helpdesk System, which is an open-source web-based platform designed for customer support and helpdesk operations. This vulnerability allows attackers to execute arbitrary code remotely when they can manipulate a specific part of the application related to type_enrichment_data. This typically requires high-privilege access, making it primarily a threat in environments where an attacker can influence administrative configurations. If left unaddressed, it poses significant risks to organizations by potentially allowing malicious actors to take control of critical systems or data, leading to catastrophic operational and security impacts.

Potential impact of CVE-2026-34724

  1. Remote Code Execution (RCE): The primary threat posed by this vulnerability is the ability for an attacker to execute arbitrary code on the server. This could lead to complete system compromise, where attackers can modify, steal, or delete sensitive information.

  2. Compromise of Administrative Privileges: Since the vulnerability requires high-privilege access to exploit, it threatens the integrity of administrative configurations. If attackers gain control over administrative tools, they could carry out a range of malicious activities, such as creating backdoors or escalating their privileges further within the system.

  3. Increased Attack Surface: The existence of this vulnerability increases the overall attack surface of an organization, particularly if it is part of a larger network. Successful exploitation could serve as a foothold for further attacks, enabling threat actors to pivot to other systems and escalate their attacks across the network.

Affected Version(s)

zammad >= 7.0.0, < 7.0.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.