PT-2026-31424 · Zammad · Zammad

CVE-2026-34837

·

Published

2026-04-08

·

Updated

2026-04-09

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.1
Description Zammad, a web-based open-source helpdesk system, has an authorization failure in the REST endpoint POST /api/v1/ai assistance/text tools/:id. Context data provided for use in the AI prompt was not properly checked for user access permissions. This allowed unauthorized data to be included in the AI prompt. A user requires ticket.agent permission to utilize the affected context data.
Recommendations Update to version 7.0.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34837
GHSA-89VV-6639-WCV8

Affected Products

Zammad