PT-2026-98939 · Zammad · Zammad
CVE-2026-56725
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zammad versions prior to 7.0.2
Description
An unauthenticated remote attacker can cause a denial of service on a production instance. This occurs because the
import check and import status actions lack the setup done response guard, allowing them to execute on fully configured instances. A request to the endpoint "/api/v1/import/otrs/import check" triggers a retry loop against a blank OTRS endpoint, blocking a request worker for approximately 115 seconds. Sending a few requests per second can saturate the Puma worker pool, rendering the system unavailable as long as the traffic continues.Recommendations
Update to version 7.0.2.
Exploit
Fix
Missing Authentication
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zammad