PT-2026-98939 · Zammad · Zammad

CVE-2026-56725

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zammad versions prior to 7.0.2
Description An unauthenticated remote attacker can cause a denial of service on a production instance. This occurs because the import check and import status actions lack the setup done response guard, allowing them to execute on fully configured instances. A request to the endpoint "/api/v1/import/otrs/import check" triggers a retry loop against a blank OTRS endpoint, blocking a request worker for approximately 115 seconds. Sending a few requests per second can saturate the Puma worker pool, rendering the system unavailable as long as the traffic continues.
Recommendations Update to version 7.0.2.

Exploit

Fix

Missing Authentication

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56725
GHSA-45CX-9MRQ-MMCJ

Affected Products

Zammad