Denial of Service Vulnerability in Zammad Helpdesk System
CVE-2026-56725

8.7HIGH

Key Information:

Vendor

Zammad

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-56725?

Zammad, an open-source helpdesk and customer support system, is susceptible to a denial of service vulnerability. An unauthenticated attacker can exploit this issue by sending a series of POST requests to the endpoint /api/v1/import/otrs/import_check. The requests cause a blocking of the Zammad worker process for approximately 115 seconds for each request, effectively saturating the server and denying legitimate users access to the helpdesk functionality. Notably, this attack does not require any specific knowledge about the system configuration or valid user credentials, as it can be executed with just the hostname. The vulnerability has been addressed in version 7.0.2, which includes a fix eliminating the potential for such denial of service attacks.

Affected Version(s)

zammad < 7.0.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.