CVE-2026-34248

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority, custom ticket attributes for internal purposes). This was the case when a customer opened a ticket from another user of the same shared organization. They are not able to modify these field. This vulnerability is fixed in 7.0.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zammad:zammad:7.0.0:*:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) Zammad es un sistema de mesa de ayuda/soporte al cliente de código abierto basado en web. Antes de la 7.0.1, los clientes en organizaciones compartidas (lo que significa que pueden ver los tickets de los demás) podían ver campos que no están destinados a los clientes, incluyendo campos que no están destinados a ellos en absoluto (por ejemplo, prioridad, atributos de ticket personalizados para fines internos). Esto ocurría cuando un cliente abría un ticket de otro usuario de la misma organización compartida. No podían modificar estos campos. Esta vulnerabilidad está corregida en la 7.0.1.

17 Apr 2026, 15:48

Type Values Removed Values Added
References () https://github.com/zammad/zammad/security/advisories/GHSA-prww-84vh-w978 - () https://github.com/zammad/zammad/security/advisories/GHSA-prww-84vh-w978 - Vendor Advisory
First Time Zammad zammad
Zammad
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.7
CPE cpe:2.3:a:zammad:zammad:7.0.0:*:*:*:*:*:*:*

08 Apr 2026, 19:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 19:25

Updated : 2026-07-24 22:10


NVD link : CVE-2026-34248

Mitre link : CVE-2026-34248

CVE.ORG link : CVE-2026-34248


JSON object : View

Products Affected

zammad

  • zammad
CWE
CWE-284

Improper Access Control