Improper Privilege Management in Zammad Helpdesk System
CVE-2026-34782
5.3MEDIUM
What is CVE-2026-34782?
A vulnerability has been identified in the Zammad Helpdesk System where the REST API endpoint, specifically POST /api/v1/ai_assistance/text_tools/:id, fails to enforce proper user privilege checks. This flaw allows unauthorized users to access and utilize the text tools functionality, posing a risk of misuse. Versions 7.0.1 and 6.5.4 have addressed this issue, emphasizing the importance of ensuring users have appropriate privileges when accessing sensitive API functions.
Affected Version(s)
zammad >= 7.0.0, < 7.0.1
